Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips-dev, 1.37-debian13-fips-dev, 1.37-fips-dev, 1.37.6-debian-fips-dev, 1.37.6-debian13-fips-dev, 1.37.6-fips-dev

Index digest:

sha256:76dff4050eb5c68eb035d047cfbb1c80c3eac91ee2cad46c4c1b340c2c4215da

Manifest digest:

sha256:b3b76efaa8b876e78c4bd26622681fc52aaeffad7790ac1066c19213cb5a3fc0

Size

53.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:4a5a6b44f5570c74db186ec32debe782bcd51fb368ab2157ce7e574c00f67ada
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:720f102bf34e15edd596a6954fd9dd27238a9f02c50df8a2988fa31bb2f4e158
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:59b5aadf191e92cd20951522b0107d8bfd8a27e57b6cf495cc2aed7ae600371c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b82a75b868f80052667283c747d11cd01e48bf4349a631ea196b8dadb622adb1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:e696f6e9d1658e04afef68713ddd892e84b46d0122d00568e8821ec46864d31a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:6a51b9cf04ecdbeb49cac45a8ce993458ff0c714f60ecc284092120835713f86
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:68e65dd620320059c0e0a8e395d0b0c25aea4141cfdf8af7c8569037dfe001ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:3a4aa4016bd0bf540004b360a41c5af9fb4658f025aae94ce25940b5e46ac76e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:308036030497e61b5e1ba02d996b96d41f05e0026b0139704116774a23c3d019
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:de7018e890c2ef43130e7a91fc97299a446c7863c219d95a5c4b0d82d160a417
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:b4c14fe8c6dbc691d6e29ebb9225d5950689e4389fa0ee5a2e942af875305734
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:32184de59725784e17299c3e52f3b08c72c8a30bb20d5a267addd420aaa039cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:698019098de86784d2459113ad2f9a00466cf28f7544250fdae006139c6e06be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:bb73baa63eb602b3ff06202c6380186627ccceda5cd575c02ff4d06120a734de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:c58f46ef21ee5d26ba2462d8cafbd353a600f68886627e14028ef5b9259203f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:3171ea02a5c9c68f5478b74c3df763c9a9408dbefeeadd3409602d7ea2db9fa5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:10d1a25194aea1fc8fcd16d7eee7a712e76e92ca97c92fe33a400506290c3d2a