Sign inSign up
Cilium Envoy

dhi.io/cilium-envoy

Cilium Envoy 1.19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.8-debian-fips-dev, 1.19.8-debian13-fips-dev, 1.19.8-fips-dev

Index digest:

sha256:0f96df030c84bdce2090dfb2b5c699c5f0d56c10085379bd784d57edd4e70e09

Manifest digest:

sha256:976166db2efdefaab1b3ed585c8786925223506fa969e86ad683c36052aa992b

Size

56.05 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cilium-envoy:1.19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cilium-envoy:1.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cilium-envoy@sha256:ae583b8c2472cb9e21a61e4f9fe478f69a0f8d823d6f45013d6088d9e5390163
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cilium-envoy@sha256:0ad4cb4b837c6bfefedfbd57ee656258b05c86becbbc35af744a963c650a304c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cilium-envoy@sha256:12be423f711a2071e1f9a967a6bf4c80ba60e0f142eb3640ab7237885bba10ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cilium-envoy@sha256:6fc6835bbd9fc19f1c7ee9ce7d793ca300191b0cd76529be058877de6dbe96aa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cilium-envoy@sha256:a20b7814b9190240f3106a293aa6c309337a201ce766f2833aa15aa3cb196ee7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cilium-envoy@sha256:a974c80575a8db57b67c811c002a78c4640f7c33bc44c2b4250331089f96eedb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cilium-envoy@sha256:a069a4ed8bc7f299f1922b7dd5f2cb92aa208b6fb321ab6470e3870ae2f96b25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cilium-envoy@sha256:caf2719a329bb00898eef67c128c7d4a113105927c1796ec657e708c683d20c7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cilium-envoy@sha256:7825b3558d52965c7c77ba2062c46dd94ee86636569e271d3a1f3480d42917c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cilium-envoy@sha256:706509fb0a64836496cfd90428d1cf11957706e7c8f79977044f63584dbf29ce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cilium-envoy@sha256:690dfa48b34b08075a4c7a7a859843535003c718da5d245848db2b4b55686cc3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cilium-envoy@sha256:8247f4bb5487d83a6b38e1011056e678681379167bdd59e9ccad5d96d42354bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cilium-envoy@sha256:c32c65aa700f5c71de852ac76854fb9ff8e548b1557f7ca0df5387ad391ab77e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cilium-envoy@sha256:59581b97a92f45fb0fa1375b236f4ccb98db43e3eb40177f164d62bd2402f61b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cilium-envoy@sha256:fdd7f0ed35fc1c1d8b97731680e3747362465a8b64059ef74b1cff317b0c49b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cilium-envoy@sha256:d153b07cb1863fa2460860c79f53db6240e4cba3d0d09a90659c1c666d1d723b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cilium-envoy@sha256:562ad5c6832f733e277dca5add62abb930b47264176e9d1b0ae18faa7afcf5dc