Sign inSign up
Apache HTTP Server

dhi.io/httpd

Apache HTTP Server 2.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.4-debian-fips, 2.4-debian13-fips, 2.4-fips, 2.4.68-debian-fips, 2.4.68-debian13-fips, 2.4.68-fips

Index digest:

sha256:f73ff33e7d94ac8ee1179415617bab92e6f3dd2f867d912ba28469743c622df5

Manifest digest:

sha256:202d08454428c74f72cd71bf60e9a94bb10514b399c4b4569fdbcc906c2da30e

Size

23.21 MB

Last pushed

2 hours ago

Vulnerabilities

1
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpd:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpd:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpd@sha256:54169db5695976eadbbd96a13b9da31187b1237c4c709257f8f0e312c9183651
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpd@sha256:191dbf958f487e8d83fd4484017fc2a892f09ab8098d5cbfcbf7625fd4f3acd0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/httpd@sha256:5b839e2966b4328515fc8a845cedba8dedc74f52c809ea134f1b69e8414302bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpd@sha256:110ed7fb9ff8672bac732a8fe345d691b08f53cb955da42302b70c81bc604678
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/httpd@sha256:60ca7080dd16ae4d5dfcdd69ae6602023df7d8b9846a39a431dacdd2e12c8836
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpd@sha256:a774965ef10ccbc89cf6b63f110e356685f75c04682cf778eda5d13ada29bb83
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpd@sha256:a7aec74c0fdfade11e4ca3eba304e6398dfddd5cc5102c0449eb9c37bfbd4620
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpd@sha256:3681637abdf90c459620a6a093c2d570aa2295a81b455d254116ac02fd398249
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpd@sha256:00200e4aec989bb88ff47ed22c62b1f77f16e76c3ec17d676c8fd36f0172f1b9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpd@sha256:29457c4ba80af103c7c94001059671c8d3e70344392e95feee345822f768a7f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpd@sha256:05d411fd4f1c905f7d6b3459f86d947406b1f7d946b47fd91925927d5aa1d561
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpd@sha256:f45b5a944c86e736d0ad6548fb0d1259fd27912dc3b7dfb9134dadd59d8b5428
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpd@sha256:2a1470813a5d70aa46fd3525bb9d9616eeaa8b9ef8c1fb14de32a528c8a76caa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpd@sha256:b5cec01abe7066755bd2ed77917a75406a47d16f70dafb9efa6c245874d9352e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpd@sha256:b429fffedc28227a9cf114ebf57244466a01c78b4d1a84128481e80fc42d1897
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpd@sha256:bd98d5dd77c2d633b299826c4efb35a903291abd15bb23f8dea7d3fbaced878c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpd@sha256:27a364bee7b270c57c4bd6a4f5b612a3ea3cb87d7d4ef84cba15b2d84f52cde2