Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.2-debian-dev, 1.39.2-debian13-dev, 1.39.2-dev

Index digest:

sha256:3995f6cf7df05b5997b12307e18332635f4b708370f98dd6a50af6d62b2b11ab

Manifest digest:

sha256:5ce1d9efcb7a98beb5104759d23e1e87294a48c5b17cd623ce8bfd9d13422472

Size

57.06 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:8115c0ebb23195f48ca49a3cec6bd14d555cb18cfa42798b955ab501dff74334
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:ba8e940c2d225eacdc7e530dc6fd158373696f7e667630b1ef9a1e3cda2c50e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:f3082a8e31cf75ea12feaee35bfe4c83b5a7fabeef518360b00bf66afc8692e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:b8156b288ce9f7338936c8d9b88e026e68d775080547cedd107212473bb16d84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:675fe5f6ed63095ca26f6bd3ce0c86fb6fcb02bce998248d60f53f1e2ce4fe7e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:dc256def31f7d5c5e2996acc1c0f9297973efe5d5e2e08110b77cc1d3da89781
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:d138c9bde5ed621a193679850b1c950bdc95743521d5b38e70e0e10dee4ea406
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:f037c7271a60732263d79cd14c7fdf9efc24b749482eddc13f884b0c75d44f6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:c11a517c6f829738f6e1e69ed4f4debb9fd86d173923d3010aa33d2f02fef37e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:7a6441744a10ab8e9f8372bf44e226fa23d25ac1cddc422cd48f21f4fb99544a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:20e1d44e50df40bd6b92a9323fa555d6e616f5e2e6e9327f326e898a6fe5e52f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:c1ec1b8efceb3e3d2b630804690184ffc31f332b392fe8b636627c162306f828
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:0a5a8551f2014ac5be1be85d5a79bc728cd7536d9866e02d5dcacd327d0b52fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:123939b1dc31e734368d36a2860df030f3d8bc3948f3d2f2e672c808b7ce86a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:eb818fadc978b5242fa244ce51a85ad2e9e69f879ddd667eebf25825ec211980