Sign inSign up
Caddy

dhi.io/caddy

Caddy 2.11.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.7, 2.11.7-debian, 2.11.7-debian13

Index digest:

sha256:839a9da71f1a1b3e0c604f6240ad32cf00eadd70628734b1c60ad073545ca514

Manifest digest:

sha256:ef2d526dfc85f67977aa3d27754d11ee931eeecf4618c4da4d62e8c5eebb4f8b

Size

18.10 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/caddy:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/caddy:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/caddy@sha256:d0a0f34467c0d48079c4e60518195f1d8815e45e278142c0152d0e3c7977d9b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/caddy@sha256:28ae6da0b2a1f03f1e7bb6192081567c050409b1a2111afcd7c4d4f288f6caa0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/caddy@sha256:541d8a2cad1a0512aee983a248c624d72dbe3534d2e6d2124c74e4be42ea27d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/caddy@sha256:0a8d26c19582ff778d219af6eb085d75bd73d22d80e1eb10d829e71bc3e0d8dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/caddy@sha256:ab19dc55b7ab7117e4ca65cff7c6325779d9e0b05e04f63e43b2b70f93aa33bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/caddy@sha256:f2df7b3ae946f6c7d3d25ac05adeff6a4c63f3b5b1afbb6149c49c47e269ace8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/caddy@sha256:ff6bee9f83d1337d191c7c0c88303797a5091b9e940490b5a1b7090937c4ff89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/caddy@sha256:c375bf315a239de947a4e7d7cb42a5d5c6370b79206cf92f6293a848ce423b53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/caddy@sha256:a28cff4aad1e0d8fd4623afa159b9ea2eb37a65d11bc533c093bc65b0a9f1439
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/caddy@sha256:8ace8414936025c10285b3de9598ade1a4fdeecc6eb0eac4411f1dade5fa4015
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/caddy@sha256:efd6573e9bb5ff87d345696cc5d18d48f5571204058eae843e26d5c6533cf14f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/caddy@sha256:f709e7722575a24bc783efcc0a4c3c6ce9b4d1e78540e3377213a852fb903418
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/caddy@sha256:5b43c570d5ed114351152a7d8b7a12137c9c569387f72a8f8fe8f87af679cc2f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/caddy@sha256:8adcf92e158f8502a9a2a0912f4b6970c21a7bf71c068dc706990d8663b1968b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/caddy@sha256:253fac6bcb43565f94e858ed5b1b18cd0fac0040a3fe40766aba4c85eec366af