Sign inSign up
Caddy

dhi.io/caddy

Caddy 2.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.11-debian-fips-dev, 2.11-debian13-fips-dev, 2.11-fips-dev, 2.11.4-debian-fips-dev, 2.11.4-debian13-fips-dev, 2.11.4-fips-dev

Index digest:

sha256:ca4dda250ef09e5b657ce212b644350fb59799bc9ed0bb77d094e988d01e5148

Manifest digest:

sha256:7e31b6d6aee4af6bb01da40106a3307b6db1ac4e5f9c1df7eabce52095858eb2

Size

56.20 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/caddy:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/caddy:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/caddy@sha256:7a8221b3643d1de0837beee322e1b8a22ac2433b813ee268a5689ceb3fcc6a8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/caddy@sha256:88032fde897563893cc44017d2c2ea4301c997bbf3358d0767e0018dda6b69d0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/caddy@sha256:78e1e3b8e1e742f0f4e1376c0415c0df3e394c712fb5a8f9d6901ae17ad3e1ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/caddy@sha256:786c2d4313c3615c2aed2c561f4c5fe86fa3ed07d5e1ba4213779438da468b2e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/caddy@sha256:5da9cfbba4070c7658e41a584ae4121548d282a4f6858f9a83277d8215ded225
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/caddy@sha256:bf7087162fd00d8bd1876fb355632377b223390a44f9db19d067de65b89fb6bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/caddy@sha256:800e9073ce84275d15e049f30e39482a6be171aa2c7a5a2874e9f9cf04ba2387
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/caddy@sha256:4fa35b61c028fb07ab904e6a06861d0572a0687caa0999d8c2b8cb9cc9c46362
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/caddy@sha256:9cea8263cc7ac3b721029dced7ed1282d12da2d64e450597c8b3b94697ff9ff0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/caddy@sha256:aee5aec01debc13ff241628dc1253158bf0aa2fa4383350da2b0b246cecaa7bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/caddy@sha256:60d118e5f80061e3190b92a9ec043166ae88077d7f0664e7493686bbf0f16655
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/caddy@sha256:490a6866145e754a5ada2c62c9381d3a17ef675ff74143b37dcbcd953aa3276b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/caddy@sha256:b98e5bd0c9218d6cb51f1a16d3144c74c042b38ed2dedc2350482265cd5091a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/caddy@sha256:798ae6f107dfc5de8383eed48eee1b28da415e2e36197734a9ebf4fb43ec332c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/caddy@sha256:250e13e8e257acfdaaa8382e1f0c97be3dac6a5e5438dc9ac0c2400775887e06
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/caddy@sha256:2a091dc53ed8b3fdf3e7125a0efe52df69b674ed1b0523c8672e262685e08e4c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/caddy@sha256:2def291eb5c1a4d0b539d53f47773999afabeae085925667219f38f29b86ff5e