Linux workstation

Debian 13 (Trixie) native package

caddy

Fast, lightweight web server with automatic HTTPS

Packages / Debian 13 (Trixie) / httpd / caddy

Package: caddy (2.6.2-12+b3)

Maintainers:

Debian Go Packaging Team

External Resources:

Homepage: [github.com]

Fast, lightweight web server with automatic HTTPS

Other Packages Related to caddy:

  • dep: [libc6] (>= 2.34)

    GNU C Library: Shared libraries

  • dep: [libzstd1] (>= 1.5.5)

    fast lossless compression algorithm

  • dep: [libnss3-tools]

    Network Security Service tools

  • dep: [media-types]

    List of standard media types and their usual file extension

  • dep: [passwd]

    change and administer password and group data

Download caddy

ArchitecturePackage SizeInstalled SizeFiles
amd6411 MiB44 MiB[list of files]
arm648.2 MiB37 MiB[list of files]

Chemins de fichiers du paquet (39)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /etc/caddy/Caddyfile
  • /usr/bin/caddy
  • /usr/lib/systemd/system/caddy-api.service
  • /usr/lib/systemd/system/caddy.service
  • /usr/share/bash-completion/completions/caddy
  • /usr/share/caddy/index.html
  • /usr/share/doc/caddy/changelog.Debian.amd64.gz
  • /usr/share/doc/caddy/changelog.Debian.arm64.gz
  • /usr/share/doc/caddy/changelog.Debian.gz
  • /usr/share/doc/caddy/copyright
  • /usr/share/doc/caddy/README.Debian
  • /usr/share/doc/caddy/TODO.Debian
  • /usr/share/fish/vendor_completions.d/caddy.fish
  • /usr/share/lintian/overrides/caddy
  • /usr/share/man/man8/caddy.8.gz
  • /usr/share/man/man8/caddy-adapt.8.gz
  • /usr/share/man/man8/caddy-build-info.8.gz
  • /usr/share/man/man8/caddy-completion.8.gz
  • /usr/share/man/man8/caddy-environ.8.gz
  • /usr/share/man/man8/caddy-file-server.8.gz
  • /usr/share/man/man8/caddy-file-server-export-template.8.gz
  • /usr/share/man/man8/caddy-fmt.8.gz
  • /usr/share/man/man8/caddy-hash-password.8.gz
  • /usr/share/man/man8/caddy-list-modules.8.gz
  • /usr/share/man/man8/caddy-manpage.8.gz
  • /usr/share/man/man8/caddy-reload.8.gz
  • /usr/share/man/man8/caddy-respond.8.gz
  • /usr/share/man/man8/caddy-reverse-proxy.8.gz
  • /usr/share/man/man8/caddy-run.8.gz
  • /usr/share/man/man8/caddy-start.8.gz
  • /usr/share/man/man8/caddy-stop.8.gz
  • /usr/share/man/man8/caddy-storage.8.gz
  • /usr/share/man/man8/caddy-storage-export.8.gz
  • /usr/share/man/man8/caddy-storage-import.8.gz
  • /usr/share/man/man8/caddy-trust.8.gz
  • /usr/share/man/man8/caddy-untrust.8.gz
  • /usr/share/man/man8/caddy-validate.8.gz
  • /usr/share/man/man8/caddy-version.8.gz
  • /usr/share/zsh/vendor-completions/_caddy

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Utiliser ce paquet

OpenFactory peut démarrer ce système d'exploitation dans une machine virtuelle du navigateur, ou lancer une construction qui inclut le nom natif du paquet de cet enregistrement.

Versions, suites et dépôts

Chaque ligne est une métadonnée d'index pour une version, une architecture, une suite et un dépôt. Noms, URL et tailles viennent de la source ; un lien est un emplacement de récupération mutable, pas une redistribution OpenFactory.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
2.6.2-12+b3trixie / mainamd64Debian 13 · main · amd649.6 MiB39 MiBpool/main/c/caddy/caddy_2.6.2-12+b3_amd64.deb
2.6.2-12+b3trixie / mainarm64Debian 13 · main · arm648.2 MiB37 MiBpool/main/c/caddy/caddy_2.6.2-12+b3_arm64.deb
2.11.2-1~bpo13+1trixie-backports / mainamd64Debian 13 backports · main · amd6411 MiB44 MiBpool/main/c/caddy/caddy_2.11.2-1~bpo13+1_amd64.deb
2.6.2-12+deb13u1trixie-security / mainamd64Debian 13 security · main · amd649.6 MiB39 MiBpool/updates/main/c/caddy/caddy_2.6.2-12+deb13u1_amd64.deb
2.6.2-12+deb13u1trixie-security / mainarm64Debian 13 security · main · arm648.2 MiB37 MiBpool/updates/main/c/caddy/caddy_2.6.2-12+deb13u1_arm64.deb

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Empreintes et dates d'observation

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

2.6.2-12+b3 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 5c6c461e13c02916681f20faedf0132762afd59dd3637a2077ab534ec1a6e4be

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '5c6c461e13c02916681f20faedf0132762afd59dd3637a2077ab534ec1a6e4be' 'caddy_2.6.2-12+b3_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

2.6.2-12+b3 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: b20fbc8bb32e4dcf89ea5b0c31c873c740687f9ff83606aee76d77cc2f46d5c4

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'b20fbc8bb32e4dcf89ea5b0c31c873c740687f9ff83606aee76d77cc2f46d5c4' 'caddy_2.6.2-12+b3_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

2.11.2-1~bpo13+1 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: e11c13b0e0e62ec7b28a04add94b9af276c27fa8e7ee6c0da6165fb7cb8c3989

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'e11c13b0e0e62ec7b28a04add94b9af276c27fa8e7ee6c0da6165fb7cb8c3989' 'caddy_2.11.2-1~bpo13+1_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) backports main amd64 revision trixie-backports-main-amd64:d39821bb4fc48252327fb05d82ee36a9b8a1446ae693561c7389741ccb0a2c7b

2.6.2-12+deb13u1 / amd64Observed Aug 11, 2026 to Aug 30, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: f173515859f273c97219cc242d625a64650fefdd136a9570acb1b5f7581c9786

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'f173515859f273c97219cc242d625a64650fefdd136a9570acb1b5f7581c9786' 'caddy_2.6.2-12+deb13u1_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian Security revision trixie-security-main-amd64:dc1fe8c451d5ad17fe1ab51a53a09aa339509450dccf3cc574b243af9d7bd45e

2.6.2-12+deb13u1 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 0b2784bed2ed2f163240edb7a827b1398fb802975fff784263e891d02d316fbc

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '0b2784bed2ed2f163240edb7a827b1398fb802975fff784263e891d02d316fbc' 'caddy_2.6.2-12+deb13u1_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) security main arm64 revision trixie-security-main-arm64:a1606cb4e67822be93a6484199cd3ca52e27a8be038314abcac98bbd484c43d8

Complétude de la fiche

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 95/100

Field source: Debian 13 (Trixie) backports main amd64 revision trixie-backports-main-amd64:d39821bb4fc48252327fb05d82ee36a9b8a1446ae693561c7389741ccb0a2c7b, Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3, Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908, Debian 13 (Trixie) security main arm64 revision trixie-security-main-arm64:a1606cb4e67822be93a6484199cd3ca52e27a8be038314abcac98bbd484c43d8, Debian Security revision trixie-security-main-amd64:dc1fe8c451d5ad17fe1ab51a53a09aa339509450dccf3cc574b243af9d7bd45e. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources et provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision trixie-backports-main-amd64:d39821bb4fc48252327fb05d82ee36a9b8a1446ae693561c7389741ccb0a2c7b

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    d76b03d2e95d41787657f3526c331993526b4b17f6cc09094b0675bcbf57dc7c
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: d39821bb4fc48252327fb05d82ee36a9b8a1446ae693561c7389741ccb0a2c7b
    Observed SHA-256: d39821bb4fc48252327fb05d82ee36a9b8a1446ae693561c7389741ccb0a2c7b
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Observed SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Observed SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-security-main-arm64:a1606cb4e67822be93a6484199cd3ca52e27a8be038314abcac98bbd484c43d8

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    fb4f5284b755510aafc1d8a39ef966c7ef714aaab3ecc24baae0a67c38518ab5
    Signer fingerprint
    B0CAB9266E8C3929798B3EEEBDE6D2B9216EC7A8
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: a1606cb4e67822be93a6484199cd3ca52e27a8be038314abcac98bbd484c43d8
    Observed SHA-256: a1606cb4e67822be93a6484199cd3ca52e27a8be038314abcac98bbd484c43d8
    Result: match verified

  • Debian SecurityAug 30, 2026

    Authoritative source; repository metadata signature verified, revision trixie-security-main-amd64:dc1fe8c451d5ad17fe1ab51a53a09aa339509450dccf3cc574b243af9d7bd45e

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    fb4f5284b755510aafc1d8a39ef966c7ef714aaab3ecc24baae0a67c38518ab5
    Signer fingerprint
    B0CAB9266E8C3929798B3EEEBDE6D2B9216EC7A8
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 3, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: dc1fe8c451d5ad17fe1ab51a53a09aa339509450dccf3cc574b243af9d7bd45e
    Observed SHA-256: dc1fe8c451d5ad17fe1ab51a53a09aa339509450dccf3cc574b243af9d7bd45e
    Result: match verified