Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.3-debian-dev, 1.39.3-debian13-dev, 1.39.3-dev

Index digest:

sha256:0a69660c480f7c8eb5f926e79a471d43cfc32a764fe92719ade508b37f7b9cfd

Manifest digest:

sha256:ea04ac6fcabbd337a53dbebd1f0e19f3d3c69253e2357b154852fb219b59af4d

Size

57.10 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:857ca550645e01caabe8fab534e6b87b6c91b866a375dae9813abfe11434061c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:1e3dd6315832bb21c1c62516a3594d32d5bdc53b5d69353a6a2411e981c1234d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:9e84c58220abf2da794ee8a004f79ff09313c314f7f2d2b3d88478421ed7e636
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:c19212b2fb61e3b511d6fcc9f82f3fca275ca2e57ed7b7d017481f2334eae5e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:01c7d3dbfd75a5c6094811735c581827a6b77c6001f35632a47076051e4ac161
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:585eae6e53b3e033ddda3205d1fbc21ae50a338e35d986db7f3e270ae1f89014
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:5c762fd14d871ddad0ed07c7e1a27c8aea95cf93ea31802f4ffb74599c67be3c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:3a24812cb646d067f82e63aa574926d423918607b9f2331ba13a76a2ebe63277
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:8b4ce8aaae6c7040d2b815c9fa09a3e7c1a52d8eea3ad30f0269036a2d066db7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:2420959791de74a374368a7d5b5da483ba67c2db2733ed38a325b1c0080e5610
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:a70335e78cb2f35c3f069ae2057cea7f9eecbb99c8bd98672ee2522c9b1a5b4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:ee8a6ef4c6063be992c7c5e2a4ea915087ff15beca5764a64ca2bd10121f673d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:a88133fc601f0de07c103b5f50b2e479add028c8c2c30464b4e98eab2cfb657d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:6747b8d6f892f7f9a8aaec77631b4f056942fe2652ef630131b5d7df19903f60
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:f4d2f7692f247d40e64e6fc0ced055084c3e4fb41b0b0d5a576bc8bad20ce7b4