Sign inSign up
curl

dhi.io/curl

Curl 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.14-debian-dev, 8.14-debian13-dev, 8.14-dev, 8.14.1-debian-dev, 8.14.1-debian13-dev, 8.14.1-dev

Index digest:

sha256:4215eba42fed61f2d2e2edeae0d46378b9e3488400ca13160b6a4ce14935bc82

Manifest digest:

sha256:a0598047c8ff9f121147d097021aa4f7bd612daf420160fcb1e4ac2857eacf63

Size

27.22 MB

Last pushed

10 days ago

Vulnerabilities

0
2
0
19
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:c7ec899d83f28bd8f099fa566457827dc519ad8b972294b0464844d944405303
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:21e09d17bb3478f898447316c642854d2ddeff34e754d65e0629662b2ab76df0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:e194a6c4ed2c136c175ed49f47debfcc59fa6376b426c75455d68ec50717f455
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:1ec72c0279514c0606faaaed5c21d25365ff1ddff771e8ec817fd352e6795617
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/curl@sha256:ca1e857436058badb294f1ed6ff89226f3b5f1b39aef2c648607cf19d6074833
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:1adcc57d408385f96aa08ad096161c8c7dd280dd8700b897f0ecf52ea5a39ee0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:a88b287ef0b48d9c5b4acbd4873dfd12ed1709732944e14f588003de90e244f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:d09943b74480245213f444e3862a0e41ab6ece496dd1865254f984c5b50cf01b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:afccec112d5b9de4fc2201c6dfad8873c98ae0b6734eaabe46868f93e563c1e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:906b4d77c01a52afacae60cc484d75060b6cd2e8e29551a42f759d3e926a036d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:5df09fbccd3ca66a07646b2f3076b2f4360e0986c56c650c6bfa386ad820ee5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:f4078de43d99e4eda906a5d68d4977fd944c9c37484ec5ef771ee874a4b44ffe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:d8cdee85c1d5c919a61cc7b481e32a7824968051dee2a488ad8153fca3265c7d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:ac5b387e8b170821759d97e892c184d03b0b66ffce60151b2d1100f9d0fdf241
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:91bdbec3339d917bb0447d3c2122663daea7f0b7b46cba552c733849cb0b72a6