Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.2-debian-fips-dev, 1.39.2-debian13-fips-dev, 1.39.2-fips-dev

Index digest:

sha256:3a13d356b2856da5b398ada70be3d57b02049199829cfefc50a2019c47b898a0

Manifest digest:

sha256:33e0b5d9b5fc60d55367b96f008e4b9de56605b3f6ddc18b21f8af3de7ff0787

Size

58.27 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:b2d0195f9ac1053707582cd5a81fc8ce82568729965238f0e53220db1e3a2c6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:d5901e457056f744fb971a7f8c53314e3b8686f40eff3d61ccf36e72ed1960ce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:af9f832dc25e411cec203bd7eaeb2d36d19c68a859feaf3b0b534ca204e1b1c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:a6cfb9fdd540a486f3ea338b95f2a66e1fe93d7f3165225f6f4229b1a14856f2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:23d36e5c5ae21dc3657c657005cbbdef1a4a7c6c88d1861f3513af306fe337fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:fb8cf8958db087be6e2ba237de484baf79a7012a8dd734d12389e6d1be53ab1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:4274e70ebeda7d2e86b8cf91bfe8668dd5ff32b776cd7ad7d87f2960768c7a83
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:0d7db22b673037862935594bf448d56e2d0fd852b94afc8881628a8607134c79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:a02745f24a329eebb76c0ca8b1ffa0bf3ea7336d7e11caa0d0222bedf6d87ad4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:22e93ec8540aa740dc28b377733e99e91c554a251a9a46d6e9456c0a1ad07916
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:fb5b8d5053cca02b89c8e30d9403f0592472eb9e2e1c3c48717ddd1da2f2c5c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:9afb3a60844e1bac8da1d93b2db89f9598f87e93f8e193fc239dad3d39254412
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:31e1ebe461a3bc2bdc00c5ee2939382f0716489ad34dc8b1c2194e21c8160c15
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:5b4a8bf589498b744358f75fef9b9a4afad1bbbbf089892842e5ef782115fab8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d3e3ac14a9a4fa75ea1a370de8312d60c1dc9e345c22c4cbde87c3f4a62f0677
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:999975877ab8e04ed9ac9ab83152933cea968e97414e12fec18d19539100b8a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:ea987e7683c3d8849e6f590deb21ec81731137f16d9cb71fae7f787361644727