dhi.io/httpd
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.69-debian-fips-dev, 2.4.69-debian13-fips-dev, 2.4.69-fips-dev
sha256:caa5715d7fa174f63aff69ea137e6410f893f32256a6ef335fe957fa48af90a6
Manifest digest:sha256:90c1d9de2bca1057bea0cd80ec541bc5993a636e1c34611a9331ffecb9ba55b6
Size
34.76 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/httpd:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/httpd:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/httpd@sha256:f5155bddca552893def6ee1aad89e265f7cbce0f26b35a65b4ce32c7d838564b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/httpd@sha256:191d1bf71295519e02f51f1a00ddc7a44ab89cbb593945cfb9630258b9c2b677 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/httpd@sha256:3513bdb8f680fc038a9738c7fe384493b2e2b7e9e3e40ec7e8b639aecd3f4228 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/httpd@sha256:3234508699e97e26f151b9ad7cbedb3762310802ae000e5e87769bfd577c0516 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/httpd@sha256:5960a5a81bedff78a9b33922918b72bebc35e935a22567f6100bc9bc0d5ff33f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/httpd@sha256:3cac3b2a66ff6ec82f6f3a06c138ed9892edc4e53ee5e48437287c423be70112 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/httpd@sha256:0b1b81e76499612019192875af4df67627235d620db338c99d44817ef5cd5110 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/httpd@sha256:ef1fb2f1cd5240a814a91830ab5b95693c571aa4da0c4c338cdaf6e0594ee6d7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/httpd@sha256:1c9bded65c028d6101a0bfcf9c783993f9f1f67cf69ea8b8fb5ff47dbe79e0e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/httpd@sha256:96ae23fc46d739cb30f533d29f1bcf0f26efe03fe66559c0172aee4d9f0ddb69 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/httpd@sha256:92256a81dcaa6daba432d356da59ca35722fe4cef6f58013d7d29f79bc437699 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/httpd@sha256:4bd77a809869f5013db97ac7e5a2ca2413f8c075bc0695b541ea80b65b1ac483 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/httpd@sha256:9027e414e80e70fee152cfab5d545ba91e209e20713595585319f4f6f6a9e731 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/httpd@sha256:fb1a6e497fefe8f901231c246383ce7a40ca64ee01ec6a08d278f68b49ef4f24 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/httpd@sha256:e83fe4036175bff18dd640e001a9d2fc4b5aee77b8bd5f1414731a8f0e102f6b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/httpd@sha256:41dce603f2022bdb87afa4480d7a03727fdb1492d0a61d02104d417a4b25eda9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/httpd@sha256:33527f5c9bd3d527df47f13aea974e2fafd56d5afa11187ff4028372495a0ffb |