Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.8-debian-dev, 1.37.8-debian13-dev, 1.37.8-dev

Index digest:

sha256:d6978c8d2f8b12e95dcf1971123243ba6e62cb09325a2237d4376bf696427ae6

Manifest digest:

sha256:5ab78f8b463c2b6d4f32f7d80837453f0108a5eeea3629b20baa56e11e80fc5e

Size

52.41 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:81f813ec737ff4a54626a3f05d1e113cf59c09745bc601786a7467bf12ae5831
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:e6cf2a28241e500febdc61cdb7e6020b3e730d5cc5fdbf1876a68b53c80ebd41
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:8ef99f8ed2990170583de220b78667f6f770dca929ad198081f17a4ac511bae7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:922876f3e9b3b1d95055559cae28287e19175b92d2467c8cca43067e198c3f6e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:979b68b03389406dc6f2921a4f32dab740fcdc319753b59f107196477a1d48e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:48de26fef389ea33044322e7ebf29ab0f81e6fa37a6bfa0794d583eec5a98408
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:7b6e3ab70c6a8e5341d1e09844ed1ab1e543920d1750053b2d46d1694b9cfffd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:4cbfd4c5260209ba43b54ae9eec9ad895bd841933be0cbdac9fb13f3f5a1cfb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:def5ea58db9fd847eb9bc45273fc6d0fc12ea10445b186d423ca9377e111775a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:1b4eb68478a66fd29fad83c4ea594a4b0767ac2c062772c9d2a9e1c1f74c7a7d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:4863bcb78cf6e0d0e1c392492368981a714ec97c7f1a25106c52ed9466f7620f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:44c6496b44a673944ae7994b3c35350e701b43245702f27bb82e5275adb30cda
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:3df56d8e653c29d017e3185f69e0aa7ee55de3d1897de69908618abe2b582ede
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:3e709ab91aa397c5766559afad488ee816ca03d8e7d15880138ad34beeabd5aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:7797bd7fdc9a18371abddd49aab96a84902dd535ee7ed59a87ad0c541880942a