Sign inSign up
Caddy

dhi.io/caddy

Caddy 2.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.11-debian-fips-dev, 2.11-debian13-fips-dev, 2.11-fips-dev, 2.11.7-debian-fips-dev, 2.11.7-debian13-fips-dev, 2.11.7-fips-dev

Index digest:

sha256:21bc4d4fc077868c9048185a783daac1c3715e3a4a2aa07195a40f9e00571a75

Manifest digest:

sha256:649af66e25376a4268bb936fc5aefe6d5c68b22633227ab168d7066709193ad8

Size

57.18 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/caddy:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/caddy:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/caddy@sha256:dc6a80eac511c58a7073da2e677d7eb114504a153e1e2b5695f6e2155af3c712
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/caddy@sha256:689cc03ea7554685f14736652ad5ad2133aa638c40053fe4628faf6039d4ecb4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/caddy@sha256:4a18acaf41b181e85255e12bbc70acb730cdad2ca59f9b75f87bd3b633c645ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/caddy@sha256:047ac24ba41705cada517d5afaec787cf928192bf37022197321c1f652f16413
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/caddy@sha256:3ac5a3eaeb34406cea936cce5ebbe1ffcf19a45be54b967c9a371a712454ee44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/caddy@sha256:46a2e3c0d574f0f1f794e014576b62c886d6ad0a6043304240db59ae3ed63dba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/caddy@sha256:787b4cf6f77964d251e3f0da875e05f29e5f266d0ed06b2af66df729e144b390
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/caddy@sha256:97c0eb137de307e21540f9358c7803a4e7ce3188e0fd76410be7dfa29c7aa1b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/caddy@sha256:c98162701d4b5b25fd18055353b5b17cbd681db80c66ed602f71eb3143704217
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/caddy@sha256:76a029a8cb65d6536c10a7053f2e648d3199b42417f421dac9228cea58b055e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/caddy@sha256:d82e1453675eb51ebe818a6ba8948cd3dca7f6772bf0a5010343f38ca6c2c07d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/caddy@sha256:e0e48cd3aa8a97e69500d905b6e2c98457e94c89b19f43ee0672436027d6812b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/caddy@sha256:d43e93b6be2d7faddde032f7076d0d483f2ed3831bfcd5ddd39cb0d7195db1db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/caddy@sha256:f78b196ce5f7ec6bbd0181d7d6c191d74e633b0b01333174454898c667192ce9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/caddy@sha256:98b2dcd93f4582b18c40dcb19ffc9282b71701ec626ac04f016d9fe31d32a469
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/caddy@sha256:dc498e7f5f5ba1cbd0e8ad46d0144018f1e02053e22670270c92dbd2515264f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/caddy@sha256:24aeed98fa6a14e7f240b4e50b2cb32632e31c27b57c99fc79052172dcfc9bf7