Sign inSign up
Apache HTTP Server

dhi.io/httpd

Apache HTTP Server 2.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.69-debian-fips-dev, 2.4.69-debian13-fips-dev, 2.4.69-fips-dev

Index digest:

sha256:caa5715d7fa174f63aff69ea137e6410f893f32256a6ef335fe957fa48af90a6

Manifest digest:

sha256:90c1d9de2bca1057bea0cd80ec541bc5993a636e1c34611a9331ffecb9ba55b6

Size

34.76 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpd:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpd:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpd@sha256:f5155bddca552893def6ee1aad89e265f7cbce0f26b35a65b4ce32c7d838564b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpd@sha256:191d1bf71295519e02f51f1a00ddc7a44ab89cbb593945cfb9630258b9c2b677
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/httpd@sha256:3513bdb8f680fc038a9738c7fe384493b2e2b7e9e3e40ec7e8b639aecd3f4228
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpd@sha256:3234508699e97e26f151b9ad7cbedb3762310802ae000e5e87769bfd577c0516
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/httpd@sha256:5960a5a81bedff78a9b33922918b72bebc35e935a22567f6100bc9bc0d5ff33f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpd@sha256:8d0a140a2f61600e1aa270f6f299443bbe95d6c55e6642818121fbee4634065c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpd@sha256:0b1b81e76499612019192875af4df67627235d620db338c99d44817ef5cd5110
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpd@sha256:ef1fb2f1cd5240a814a91830ab5b95693c571aa4da0c4c338cdaf6e0594ee6d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpd@sha256:1c9bded65c028d6101a0bfcf9c783993f9f1f67cf69ea8b8fb5ff47dbe79e0e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpd@sha256:96ae23fc46d739cb30f533d29f1bcf0f26efe03fe66559c0172aee4d9f0ddb69
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpd@sha256:92256a81dcaa6daba432d356da59ca35722fe4cef6f58013d7d29f79bc437699
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpd@sha256:4bd77a809869f5013db97ac7e5a2ca2413f8c075bc0695b541ea80b65b1ac483
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpd@sha256:9027e414e80e70fee152cfab5d545ba91e209e20713595585319f4f6f6a9e731
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpd@sha256:fb1a6e497fefe8f901231c246383ce7a40ca64ee01ec6a08d278f68b49ef4f24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpd@sha256:e83fe4036175bff18dd640e001a9d2fc4b5aee77b8bd5f1414731a8f0e102f6b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpd@sha256:41dce603f2022bdb87afa4480d7a03727fdb1492d0a61d02104d417a4b25eda9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpd@sha256:33527f5c9bd3d527df47f13aea974e2fafd56d5afa11187ff4028372495a0ffb