Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.6-debian-dev, 1.38.6-debian13-dev, 1.38.6-dev

Index digest:

sha256:8e3739bca260387b6c7cc4ddfc48a370e190ef98008ea3b8e1cf02087b33c6d8

Manifest digest:

sha256:df8694612b46166c35e81747d5190bfad3beb69068f41e230d62d9dec8e1dc27

Size

56.05 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:9422506464b60e564ea18a7e914c15880280b8ff35b6e14111d7134e4ae2bf34
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:88ba9829badb6dea1a98b66c0b726bb2aeebb88fa2ef5d64056b9cc8ffddd30c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:65e47f51f9d511617d27701c4e12cf760ba8780797cf454aeba6baa01b4fb29f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:a25caecf2e4d43f3e33cb7ee1581a779292510243e7b965ffbc439369f4dc34b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:f9b53f7f398d7492d9773e9a50cb3943c9b316f2ec7a33cb2a7a9e19d8d2744e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:957029dc31187bfafc2b58d84a35377226efb51f5ec29cf0d5e94118c9ecb4ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:bab714783e9e7b1a24aa3ccbda9119ad92f36907a7f1a23fbb7180105e2591fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:f8e379f353789897e76006b6f086b39ba5116a0888936d88af8cdd7a04609f73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:0cfa192c46cc2c81f9c3d1c29cb4f92ba6964d1ada1b2dae226d0af2a57fa9c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:da8e29ab37fd1889b900301e844e75987462a089c4b700230e3c875f63b266ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:07061757dbfd100e781e8c172af59df48c8f71cf17181499c36aa65af1734f8a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:9ff781195dbfd84aa3fec9cd8a2e885443a2feceb2c8d946b222f100bf6141d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:593e09206921bb0ee2b8bc98ffd3c695ac6363595453740723fe284865b6f8ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:abc5b31f372a878e7517ece7a0296afff1b6efc2eb9c42dc6bd6712aeb856166
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:b8b5df05c7afd11ae5e42e4464e502141d84bf50e423156ce1071782fce0129c