Sign inSign up
curl

dhi.io/curl

Curl 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.14-debian-dev, 8.14-debian13-dev, 8.14-dev, 8.14.1-debian-dev, 8.14.1-debian13-dev, 8.14.1-dev

Index digest:

sha256:d63ace49cdf307b6e8009413364ce05c76aa352f861ef79e282befcf30884abd

Manifest digest:

sha256:0a24ec0079f87db7cc1dbf25e295f396f57fc410e02ad2954caff77570b62151

Size

27.25 MB

Last pushed

4 days ago

Vulnerabilities

2
5
0
13
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:404b1ad32dde13863e6b8a912d5a09a366ab639657a0619a68f0f471b2495cd0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:34ef0687cdbf3f1b3a2bd7c291eccedddd0ea665ef60bece4914a76a09f2330c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:0987383e87ab498fb7474e583c086a917bf511f4b3683a606f3641813e911814
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:0b449b5861533e0d4aaf4b20e2be78b15d013bad7270f9d111a638776b8b7b58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/curl@sha256:2b8b0c46864c06f57f6bec1314e5744d6796aef3a950cca1d6437e1c0d739243
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:f7c028b7246d83a7ab379be57e6d4a61816130a36f8096c6beacef801f0e53df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:1146e6b102e958b30a3bfa829ca05ed421bb3cea8115f887f447155ef98cd3b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:4fde368a1cf91a4d4f1fd69a6d4b8e9cd4c772d016bc3645aaec55c951d3ab5d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:87abf80f73e35e75c424e6a3b1edc1b5dc2efccbabc61cee73bb1212620ba488
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:e2339fe6cef202621d6f0021e25ab1f86e7cc62aa2fb8f58022734671fc9f121
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:c7877487ad32c0bed0e48d2059361487661f1796858f5cc84412ba7cc7a7bc8c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:07be475f8cc893b779f4a7650d9aa2083b043166bb17506775e8d1c91cf413ca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:cd2323705335d6b1c3c3229feb039b8a29e7fde8e69826d93455fef5e3cdcea2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:7bce6857c60552ffbc1bd90e5e860c6445cf0afa36dc599c51933fa73bb83bf7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:3490034798fe81572a295b1daad5c3d32a0ee397368d4fbdddd7e4c22abab1a1