dhi.io/httpd
2-debian-fips, 2-debian13-fips, 2-fips, 2.4-debian-fips, 2.4-debian13-fips, 2.4-fips, 2.4.69-debian-fips, 2.4.69-debian13-fips, 2.4.69-fips
sha256:681de143fc7d1fbb27a836327ab7fc16874fc7f0850e0c91cb17ac6f0ab23411
Manifest digest:sha256:df727f09505dd711639ee66eab548fe2205f4591a2d3bf4e7b9ce680e72d537d
Size
23.21 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/httpd:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/httpd:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/httpd@sha256:22528c0f7ca5c4f9b25c2e2cdad909dc495bd7bf8b8c8f8f8c3e262f33fc16a8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/httpd@sha256:0637f8311e2699221907b0ed231ef494ae150377818d3087f667dfd35b5f2dca |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/httpd@sha256:da5764f0afc1857ff08f853e86225d1069bef1362f08e75dda2675c34a312c33 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/httpd@sha256:9aa31550533b46aa63944e17755abafba2086407cd9e3dc265b0f82674744421 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/httpd@sha256:5984e3a1491cec19c70a0f298d98be8383753ac8557eece1cdc2daed70509d51 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/httpd@sha256:3c165612fd23543088567b1cd9abb5c085bca259cadd80e83e88fea7ce8ad9f0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/httpd@sha256:811bfa04e82daeed3ab4c2dc9cbd74afdd3b442f98ce26ac251f0eae807564bd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/httpd@sha256:a53ec1359ec1bc6b7bf3dc088beae0b84df061edabc2bfef0fceb74fb571567a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/httpd@sha256:c33de78e972111f0e8042d822414d482b9498f2b3ba3cca6b2025f8a6228ee65 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/httpd@sha256:dc46d074917f13e616f41c8a953d137c65b51d6a989e22025491ceb369c10745 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/httpd@sha256:61c2f4a35c38e9dfd43f09b48e52fe2c079847e8f07951ed8e8f4ec67d212f9f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/httpd@sha256:28a0fe7f52b456c5a2142a0d5b323f9a26bcdab34dd5b4245e438a535d1e2248 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/httpd@sha256:05da9e0ac57e264aab0a7f8a1c5e8ebc0e136feac02334ddf8eab86de457bf6c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/httpd@sha256:cec792147f89e659c36d0b31292c64a45017d3f8cd539a761e4cedc9367a6dfb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/httpd@sha256:c39644f68d4a5b681754e210a4285036e0001af9bf93c940feb124f163149989 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/httpd@sha256:3a5b020ba600deb590932e5fb4b9821a8219f5afd185d020809b9e5498cd23de |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/httpd@sha256:bb3dd783f9cc4594325935c71adee6bcad45729574ffa0eef255f8ed2b995115 |