dhi.io/caddy
2-debian-fips, 2-debian13-fips, 2-fips, 2.11-debian-fips, 2.11-debian13-fips, 2.11-fips, 2.11.4-debian-fips, 2.11.4-debian13-fips, 2.11.4-fips
sha256:be4f92d7dbc26f78fbb00279c30a0684922d8ab1745dc3e6ebb82d70c26e03a1
Manifest digest:sha256:391e5c2da0d58e803df1a4b8137f2131575a7e81ce2c41b1ade7ae6062995b01
Size
25.79 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/caddy:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/caddy:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/caddy@sha256:41dd588a22e6b5b241bb9ff7768f10347a9a0f49543d8ae03f27617bed6ce994 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/caddy@sha256:577b4e797a23681f16c4efb9ff2f5924826542187d1355ddf8a745fe548aa708 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/caddy@sha256:1cf16f10cd0efb68a1618c663beb97a50639a942fc9baed43657be4f425bd554 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/caddy@sha256:9286037282040dcd96d569ecdccd149a8e9e3d509eeb42fda9483baab5f3ef54 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/caddy@sha256:acb70c0f71ba1d35793a53e777b1008440ab94fd0d17eb66448de967eff5cadb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/caddy@sha256:758014ca492c7c33bcc2b43765ebbaff87646dbc7a683834cea1e16d75d4f0a9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/caddy@sha256:b9911708ca5b2d7027c8ce410b7a817c5949c0590486cc01218a682a5607a7af |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/caddy@sha256:14749a63c0f8cc1b42b4ca33dd761519ef3e36ee8cea41084367adabc1c87acd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/caddy@sha256:3f0e5f49c1ea0a2cb71515ab0052c53d335fa9e0700e64c7c6ea819a8f649447 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/caddy@sha256:20cec1526495d25827a0d46bfbeac52cec7754f2d63787e9ee1bd98d92590355 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/caddy@sha256:b63e772e0808e53fd62c4ce212a733b029e11e3a751a8fedc0149a8b8af3a9ef |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/caddy@sha256:975c2bea5c2db8c9f36d8891c52a2f229be9813f51f7caaa95e4120917ff7fc5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/caddy@sha256:57431532c8c6f45e0612c171c91d0f906d59ab2d042d724c45a2f2e93fe129b8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/caddy@sha256:325b3a9ad511dabd8ad5170a4af470b6c648ffc7156169a7534308cfec43bbab |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/caddy@sha256:587e2337960757317b6d57989ce1e536eb17e6c78c8d0d4eec1daaaaf1451248 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/caddy@sha256:296aa98523bb1da171adf31065ebdf00f0d03b917825fab6cc9bf47e8e4a458d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/caddy@sha256:572bde8f612ef8d2b86af45479b0093044e2b2b98adde44048d32e015c5199c4 |