Sign inSign up
Caddy

dhi.io/caddy

Caddy 2.11.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.11-debian-fips, 2.11-debian13-fips, 2.11-fips, 2.11.4-debian-fips, 2.11.4-debian13-fips, 2.11.4-fips

Index digest:

sha256:e8244b9acb1ffc26ff3a4ee7da600eb97045a1ad4d7155ca810d96d38a9c0cba

Manifest digest:

sha256:3794dc730442a854571c393d68aa18c1db411ea3ad7aaa25128ce98c59879b8e

Size

25.79 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/caddy:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/caddy:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/caddy@sha256:6361a3bd9502596a9e3cb37736a4acfdabec619d534023c0276d5affbb586b65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/caddy@sha256:8d5cf84480c4b8d52e1596754da42765457116ef9cf9056d9556ab675069e5c2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/caddy@sha256:936c1f97df9be2cb26eb8047408b80eaac22d47409d1c27ad2562b464faaab1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/caddy@sha256:1a1bed284b3d0b31ec6030d1d2afbbce2190fbb3057e8e7d4bc9cc3a8059c068
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/caddy@sha256:b0f09b9d0d53056511bfd5c1dc5b8778f0ee03ac39d513c807a5e0ca73e92a32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/caddy@sha256:62145bd98d9a57ead276b0893b03ac8d9c38de4da3c136053807ee2aab097d62
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/caddy@sha256:e74eff30e959381175fc22f0c38dbbd2948349038819da9fdad4bd2e6d764c9d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/caddy@sha256:0e202fe2429bf6adcccbb47b5d64a6f1ea7d2baa51fc7e75e6cbbdf3cfc6a953
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/caddy@sha256:9743769f5af200df5b1680cf9a1d513604a7c0f3df4eb658fd1ea8c667d20243
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/caddy@sha256:3e0f39b280fb5e649177564df9172b686d175f5700d908569cbbe1f45248112d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/caddy@sha256:4bb7e7c88ca053534dce0780996632545e7e90b383e157e62002c21cb379b65e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/caddy@sha256:e68f3e4fd4c93671c2e8dcbdc79e6cbcb078dcb5f0f929be58572fcd60e9f8e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/caddy@sha256:bb93c044504fced02319dfb6e1bee41aa8a1dd3751d68ea08bdb124eb3e30a13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/caddy@sha256:ff1033064b256660ea72a00efa57c65625f81b76504df4cb3a1da2fe3ef4006e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/caddy@sha256:fb30ad2865e8e672cf171f6217dbd6551c48612d4b0eee0208282dad2d88b404
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/caddy@sha256:e9c44afdc0653efced746ab83f72028e7d5500266780844727504073f9ca50a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/caddy@sha256:5054c43d6b3876210b141c8a2a0841f0b2ea29f3651f0954c31e4bf9236e0553