Sign inSign up
Apache HTTP Server

dhi.io/httpd

Apache HTTP Server 2.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.69-debian-fips-dev, 2.4.69-debian13-fips-dev, 2.4.69-fips-dev

Index digest:

sha256:68d4544492123c2901a18dff85a0c8f29b74a987a35e94e11ec94c8cead07de1

Manifest digest:

sha256:336695d2afe354f473584950247ac523df6bddc249dfdaf63cfc8f2d892d71b9

Size

34.77 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpd:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpd:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpd@sha256:058f25fa218b8ef6f176b231400abce3bca1d4ef725c8103fadd9d525aa45f8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpd@sha256:f6e97d99b4f937999f97a2793b1353e1af9df81d1ddab3be9a2f791ecce7bbf8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/httpd@sha256:6123c5b5e29d8c49de00379f12c22f8079026e6c72686547d156ed0e611140b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpd@sha256:ec03411dd33320f56a4f8de5dd93b6070ab7ab0edbc2cb40ec6c19576ab7c3dc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/httpd@sha256:550e7e6e2fe2094ed462f9601070b8b9b63692fe9dfb7953d14fc755e482bb60
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpd@sha256:5c642926f1aeeaa3bf8ac2f4eee83cc7d40236abb9fe9c2692c94793555fe53a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpd@sha256:87997f2dd624a34bd9d25d9cc1b56a550137ad7460ef95e2d6f30623b680efdb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpd@sha256:e229d7486cba0e7547ebc04395c93f5496a2a95524cf603cdfbebd7d32681d26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpd@sha256:ea3d4578ba66a5421a08ba48e5d46cc28ac228f888004ce53933bdf886713334
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpd@sha256:5a393d39fd7d457a25e8674251d63fa30811ab42579a38cc1a63587659539a00
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpd@sha256:00f54db3494f4b0a54db12b3df82a33d8e52194065f54405c7762eeae4019f39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpd@sha256:44eba411ab22e775df24cbd05504ac5a0282aad99007f09be52f00e2b7e8bd77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpd@sha256:7d13e4613cbe1845269d00eb7e1f087e619a4f6032e251321b98245fa216818f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpd@sha256:badbeb0484fde2d643155113753b8016e74f07b4d31f0c5651fcfc730a1527f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpd@sha256:95f7ca81f4934a99fa5ad32d09d087a456855e0022fbf6c5c2be3ce8fd4ec220
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpd@sha256:8aab8389bc25cbe9a1657c8a095f903011c5b14004e976779b620ffc355ddb85
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpd@sha256:f460df99b53b6bf980fb2209fd75d2791a67abbacbe1d179531330633478fe1b