Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.8-debian-dev, 1.37.8-debian13-dev, 1.37.8-dev

Index digest:

sha256:3a0fd07b90f5aab1ec006cbf6157bf1d3090571e3ff741eb03c358cb54b44d06

Manifest digest:

sha256:0573ffda5de58303929d90aef3d53e0464e06e264308192c314a04e76258d3bd

Size

52.41 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:68b6140483c6247f826e849f9029ef57454d5da8cb7a3a74eb208d9aa9a23444
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:adb56f1d9d5423dd6665fa990699ab8a70afd5f4081d69da926cd62d1a0fcee6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b50922b5721b6d866903dd10f74ddac697ecbc790b8a86918a21a1da06d040eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:8a8bf2562633332153488ee8951d1f85c6738ed4ee441488b0f36846f8ed4e05
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:8a5754e5a21906eae58d652d612dc8ed08860221578aad93559a4cab550e64ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:ef0b3653daeb3582a5103ea5ebdef1eb94c0a217be1135c0082db499f98c2397
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:b4ac688146f73d66090072fc6658fe360a09750c91dc06b9cd30ea2a3f11597d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:8a439b8c8632e30cd5677fcdb9d061212d4cfbe225c15060c98ceb658f07c234
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:30948c8619be80074848215b2423af9949910dc77b625ed763c008f7e712a0b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:be3b536e5c075e37929b06448834e63fc2b2e2ad71be844bca53de889f43b760
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:37d2e7f909d7dca57b3b4d3dba1efe2d59c2edb29cdff5ec723699f7b1569730
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:c30a620677928d1a2910cac546799959e132637a0944b370bab13dcd664bb8bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:b11ff08d4d546b04495284de34984d433ff9d1b5307f3834226fadba21b772be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:971d3d1fc1928af6373d8f091ed0ac920c0043428193e4209b55cc24aaa72510
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:ebe2810581f68bac3cd7a8519d098933a983640f7e571a69c00f71c01bb3e04d