Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.5-debian-dev, 1.38.5-debian13-dev, 1.38.5-dev

Index digest:

sha256:b46bfbebfa3a5cf78c4e0d7714e3a45bba7d81c218e0cb656ae9f1e768d2a14b

Manifest digest:

sha256:ffe7b602556781d3c2f44cdb3f62411c1ad73e85a68457e84147a23ad7df894d

Size

56.02 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:29e76d0a4adca24cff5162d102e1521643ef4343a562f2787bb9f3f306efe092
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:1b75c4c6b391a155c9f285116348f367dad29c96acb30a4d7a05f6ca046425d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:38f723dfcd0cbd75fb896dca3492498c292e5ee87169bfeb1470c007575cfad7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:a0e53a694e13a05317c463f4e5f7b831e4f56311b3175a303e3d387cd1eaa3c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:72c03883557ca6e2c3316144f704557eae7982589d794c768d869c677db2dc98
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:23f37b31ee8d6977e66acff352a2fd5c5ec098ed750a5e6a5db638797afeaeb6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:731e832ce96121efc4e523cd7b69defaf7550bb6ed9b967713f3d2179f2ebb54
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:3d5faba628e5d02a1d141e19bdd36b19c543727c7b9e43544fbd9e2da7bf30b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:3f4f4e63b9e11cab4a60243b0441d2481de253170a89edb3ae0464463273cfde
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:a35d1321cfa5e301befb859109d3871481ac49c48cbaec15f1ebd6365a86b703
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:65dfdfcaa7d08cb6903e2dcb7d397de6f6cf6375f019170355e5edd74cac9efb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:70dc42ad29785f257109267ba945100fc3e45ef7c43546d177e22d74872a6ebc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:fa5572767ce3e91435792cc19f202c5adea4b9011633d1477a5847bf514a064f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:3fffea3456aeadd0fc92b370c13574063a30594d919c76d47d0a97a564ed4e96
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:f6d7c95a493ccdd9980b964400b3813556e1f736d986f7bb59db64c470cbd9af