Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:4d9bed2d82e33838ddebb11a2d2b810e5ff5a6b267a76cd072f747725f444909

Manifest digest:

sha256:d23e2dd807c6c6797e34b77f1c41c0ef195acbd937de2f1cfb785a40c032fe4f

Size

57.06 MB

Last pushed

24 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:62c260dde91b98e3f23c7aaaa0bf1d8eb1eb3fffc3bd518422a54094128dec98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:fca72c192d7a2b046c731973aff483893365785968e06b96ba2c23af37201fdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:735c6ad9a4d5cfd670e3c7a4e20b3c330e94f3ccaa56eeab88c1aff42092f044
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:401f60a9c22635d9a0893935d91a272fde86c36ea9b60b5ee9dfbca145924403
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:5e408afc7f46f33247643d42fef5dfe2ce70ba41fd7c73629aad90e096cef929
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:8302cd86aa071298bcd10fa61c5cd50a2cb0d3765d9bef463ab4444a552324bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:2ae49d089e2932812993a86be729dd666e91e28ecfdb420a80e80bd90de65b6f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:f4a91724ff430afa7d163608f2d1c1fa9df84a872c13c896bb7b48e42b496de2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:a660810efaa1134de2ba97c6bd63ce6820345243529bc117fc17e81bc435bb89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d4acd98a3e32491e41ee44abcaea8456bc9dd0d92ce4842bbec487eac5e871a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:a43126c11fe2147251a20187c4c29f53405d0f943f557a635393f28598612365
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:68abb9aba0fbcc8352e0c02b97d07e522cfc8af0c6897e990f3d4cb8eb9e8b1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:b8ada9c16227271261e546f775c0319a77d519910960da3d98b612a681274cc3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:426480ef73c723612b469538c024e1e8f4114d649e04d1cf9f9ababa110d786f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:40c54c4631f240def4ccf3b76f1b2cddaae3b64571f2324d8f0cd6f69e038fc9