Sign inSign up
Apache HTTP Server

dhi.io/httpd

Apache HTTP Server 2.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.4-debian-fips, 2.4-debian13-fips, 2.4-fips, 2.4.69-debian-fips, 2.4.69-debian13-fips, 2.4.69-fips

Index digest:

sha256:681de143fc7d1fbb27a836327ab7fc16874fc7f0850e0c91cb17ac6f0ab23411

Manifest digest:

sha256:df727f09505dd711639ee66eab548fe2205f4591a2d3bf4e7b9ce680e72d537d

Size

23.21 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpd:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpd:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpd@sha256:22528c0f7ca5c4f9b25c2e2cdad909dc495bd7bf8b8c8f8f8c3e262f33fc16a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpd@sha256:0637f8311e2699221907b0ed231ef494ae150377818d3087f667dfd35b5f2dca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/httpd@sha256:da5764f0afc1857ff08f853e86225d1069bef1362f08e75dda2675c34a312c33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpd@sha256:9aa31550533b46aa63944e17755abafba2086407cd9e3dc265b0f82674744421
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/httpd@sha256:5984e3a1491cec19c70a0f298d98be8383753ac8557eece1cdc2daed70509d51
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpd@sha256:3c165612fd23543088567b1cd9abb5c085bca259cadd80e83e88fea7ce8ad9f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpd@sha256:811bfa04e82daeed3ab4c2dc9cbd74afdd3b442f98ce26ac251f0eae807564bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpd@sha256:a53ec1359ec1bc6b7bf3dc088beae0b84df061edabc2bfef0fceb74fb571567a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpd@sha256:c33de78e972111f0e8042d822414d482b9498f2b3ba3cca6b2025f8a6228ee65
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpd@sha256:dc46d074917f13e616f41c8a953d137c65b51d6a989e22025491ceb369c10745
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpd@sha256:61c2f4a35c38e9dfd43f09b48e52fe2c079847e8f07951ed8e8f4ec67d212f9f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpd@sha256:28a0fe7f52b456c5a2142a0d5b323f9a26bcdab34dd5b4245e438a535d1e2248
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpd@sha256:05da9e0ac57e264aab0a7f8a1c5e8ebc0e136feac02334ddf8eab86de457bf6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpd@sha256:cec792147f89e659c36d0b31292c64a45017d3f8cd539a761e4cedc9367a6dfb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpd@sha256:c39644f68d4a5b681754e210a4285036e0001af9bf93c940feb124f163149989
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpd@sha256:3a5b020ba600deb590932e5fb4b9821a8219f5afd185d020809b9e5498cd23de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpd@sha256:bb3dd783f9cc4594325935c71adee6bcad45729574ffa0eef255f8ed2b995115