Sign inSign up
curl

dhi.io/curl

Curl 8.x

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.22-alpine, 8.22-alpine3.24, 8.22.0-alpine, 8.22.0-alpine3.24

Index digest:

sha256:e21bda9b9f49d9116cec56c7309b4d267f0f9ec5c6c73eb124d2d02c9f9bd319

Manifest digest:

sha256:089dab3ab47ec92957acabc07a8f085f96ccf51a8158b6b0c8e183342b56371a

Size

4.92 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:b08f5858db9da88600c2fa098aa7332319c231823c0fa32c5794498a74dda17b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:a367e5b7112eb6e75f7cfb4f41a879aaceaff0d647e43f24de54efe21e82ed60
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:2c139c55e583bdf6c7ebd610643c709c16d2837468d6a4fe70b2d5f426202bcf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:a0a1d139fea4c3238ce4b3795562d9e5a091f5f8ecd0e38e24580e14d1635282
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:8b9a6c8d34f7db46fba174b9886649eef069c44b50686c2c64db2f3dd7c56208
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:5c75b27ce8096e13aaf2e38f993b1c7a588248684a4880a87071b51c848447c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:8ec6ac4d489af01ba4760940206154d5fc80d76d3561b5c90c8c51629a7aea70
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:ad5480381d651d90320d9c1e432b0a387b7616ac8d455fc5847826b397f58f2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:10570357b79921d9925418888c46a04edddc65ee03ed49cdc9f9b8c478a69069
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:7216904b9434c4901b35c770beddd979d607fbc519a8b14695611ac53de84ea1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:b4db94da0a1ac1413db1e1b3524d862bcf7ef67f2bd3481d8f5bec3ca022a9b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:47c54f146eeb73449ac9deea437a7cd34a532348fd8953af2144a27f91d7ff09
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:baf164fb9754e8502b5e9be9246f6dd696947c5e2ac45d89524d63eb95d4aa9d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:4444477229e5b21b9e9ca3f2a1536486490d784e6fce3511b2b2c8fd44613b46