dhi.io/curl
8-debian-dev, 8-debian13-dev, 8-dev, 8.14-debian-dev, 8.14-debian13-dev, 8.14-dev, 8.14.1-debian-dev, 8.14.1-debian13-dev, 8.14.1-dev
sha256:d63ace49cdf307b6e8009413364ce05c76aa352f861ef79e282befcf30884abd
Manifest digest:sha256:0a24ec0079f87db7cc1dbf25e295f396f57fc410e02ad2954caff77570b62151
Size
27.25 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/curl:8-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/curl:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/curl@sha256:404b1ad32dde13863e6b8a912d5a09a366ab639657a0619a68f0f471b2495cd0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/curl@sha256:34ef0687cdbf3f1b3a2bd7c291eccedddd0ea665ef60bece4914a76a09f2330c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/curl@sha256:0987383e87ab498fb7474e583c086a917bf511f4b3683a606f3641813e911814 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/curl@sha256:0b449b5861533e0d4aaf4b20e2be78b15d013bad7270f9d111a638776b8b7b58 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/curl@sha256:2b8b0c46864c06f57f6bec1314e5744d6796aef3a950cca1d6437e1c0d739243 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/curl@sha256:f7c028b7246d83a7ab379be57e6d4a61816130a36f8096c6beacef801f0e53df |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/curl@sha256:1146e6b102e958b30a3bfa829ca05ed421bb3cea8115f887f447155ef98cd3b8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/curl@sha256:4fde368a1cf91a4d4f1fd69a6d4b8e9cd4c772d016bc3645aaec55c951d3ab5d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/curl@sha256:87abf80f73e35e75c424e6a3b1edc1b5dc2efccbabc61cee73bb1212620ba488 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/curl@sha256:e2339fe6cef202621d6f0021e25ab1f86e7cc62aa2fb8f58022734671fc9f121 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/curl@sha256:c7877487ad32c0bed0e48d2059361487661f1796858f5cc84412ba7cc7a7bc8c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/curl@sha256:07be475f8cc893b779f4a7650d9aa2083b043166bb17506775e8d1c91cf413ca |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/curl@sha256:cd2323705335d6b1c3c3229feb039b8a29e7fde8e69826d93455fef5e3cdcea2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/curl@sha256:7bce6857c60552ffbc1bd90e5e860c6445cf0afa36dc599c51933fa73bb83bf7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/curl@sha256:3490034798fe81572a295b1daad5c3d32a0ee397368d4fbdddd7e4c22abab1a1 |