Sign inSign up
Caddy

dhi.io/caddy

Caddy 2.11.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.11-debian-fips, 2.11-debian13-fips, 2.11-fips, 2.11.4-debian-fips, 2.11.4-debian13-fips, 2.11.4-fips

Index digest:

sha256:be4f92d7dbc26f78fbb00279c30a0684922d8ab1745dc3e6ebb82d70c26e03a1

Manifest digest:

sha256:391e5c2da0d58e803df1a4b8137f2131575a7e81ce2c41b1ade7ae6062995b01

Size

25.79 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/caddy:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/caddy:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/caddy@sha256:41dd588a22e6b5b241bb9ff7768f10347a9a0f49543d8ae03f27617bed6ce994
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/caddy@sha256:577b4e797a23681f16c4efb9ff2f5924826542187d1355ddf8a745fe548aa708
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/caddy@sha256:1cf16f10cd0efb68a1618c663beb97a50639a942fc9baed43657be4f425bd554
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/caddy@sha256:9286037282040dcd96d569ecdccd149a8e9e3d509eeb42fda9483baab5f3ef54
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/caddy@sha256:acb70c0f71ba1d35793a53e777b1008440ab94fd0d17eb66448de967eff5cadb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/caddy@sha256:bafdf149f1b6232f21f05657b85d581ebfca86722f38aabdd3661a5df8ae8b42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/caddy@sha256:4c89a608adb35a464c708716c3472c51e57c52160004d220c59d6fc1bc937553
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/caddy@sha256:14749a63c0f8cc1b42b4ca33dd761519ef3e36ee8cea41084367adabc1c87acd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/caddy@sha256:3f0e5f49c1ea0a2cb71515ab0052c53d335fa9e0700e64c7c6ea819a8f649447
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/caddy@sha256:20cec1526495d25827a0d46bfbeac52cec7754f2d63787e9ee1bd98d92590355
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/caddy@sha256:b63e772e0808e53fd62c4ce212a733b029e11e3a751a8fedc0149a8b8af3a9ef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/caddy@sha256:975c2bea5c2db8c9f36d8891c52a2f229be9813f51f7caaa95e4120917ff7fc5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/caddy@sha256:57b90ff3a77cb0854c6a93e59809ffe7f7d0c664cdc2a0ac2a93b1919ffcff84
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/caddy@sha256:325b3a9ad511dabd8ad5170a4af470b6c648ffc7156169a7534308cfec43bbab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/caddy@sha256:587e2337960757317b6d57989ce1e536eb17e6c78c8d0d4eec1daaaaf1451248
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/caddy@sha256:296aa98523bb1da171adf31065ebdf00f0d03b917825fab6cc9bf47e8e4a458d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/caddy@sha256:572bde8f612ef8d2b86af45479b0093044e2b2b98adde44048d32e015c5199c4