dhi.io/curl
8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.14-debian-fips-dev, 8.14-debian13-fips-dev, 8.14-fips-dev, 8.14.1-debian-fips-dev, 8.14.1-debian13-fips-dev, 8.14.1-fips-dev
sha256:591167683dec7f5e1a14326761609dc6af28f02f1e7ce4b6e8f1f5d5a142753e
Manifest digest:sha256:65a7f6ef4b3dfc60bcadd167b46f1720131577fbbf911a23e300ad76ec926c8d
Size
30.94 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/curl:8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/curl:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/curl@sha256:d0e6b8803e1db79fe579d44194229e1ba9e40c58d3208737c81396a41767b0d6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/curl@sha256:655bf41ccba90e2002c2735e01860ae5b629f379fd44f1617d3b3d1ceef68764 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/curl@sha256:d2ced8ebaccff4ea5f75c9e90b91ecd92e071b33fe725f66d1aa9d20ac17736f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/curl@sha256:5066812d7e1c3ee9e2a4061ba465f559541d010bfd47601102ae146d2afa57e0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/curl@sha256:839124dc80f9e800293cbaafc8b5af2ee2943a7f02885a8606466332b4d52f8f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/curl@sha256:9c56b8862c27a651e559916ba1ec38658911ecb1facd60d4e31254bade6fb5ea |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/curl@sha256:6116fd38884bb7b0dc5d30910169004e22033f5f5f0fb46ae8f5d87a43565722 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/curl@sha256:b819d0d63666586cca0fb72ad73f55bc2c622cf6b42032c0496b834dacc3a776 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/curl@sha256:69bfc4c855b23b1e8c9129336743bbf36e0c0fbf5fe7d9b326a6ebdc83634797 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/curl@sha256:14c2054d320b7463a02b75ff8c85641d88447bcfc2bbb0218cbe9661925dd0b7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/curl@sha256:d054d306298f4a0876e40c115c4206bed6c8876f08512af7648dfea8c8fb2843 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/curl@sha256:b7b2e5a3fdc563992cdb299e49765f7b179d86ee46f219bb4a3e646a64aa0844 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/curl@sha256:5c3c3d50beca22ee75a273052290cf24569f55cd75c64a07a0d848c58b6c12e9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/curl@sha256:10f12859a3397bbd4effeb4ab3b6fc606632abeeec38521a0fb13799fed57d3d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/curl@sha256:a80452d2bfaea495da92f280084bd6ef6e7bee505a1030b5daf8da5eae8a92eb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/curl@sha256:7ada8aac5925cc1d8d450adf756001eb858b01f71230e84885a7fcfc6708bb9d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/curl@sha256:27884d2eb0a86652b440b1c314afcb070f150d756b1e9983801cc852db5c17e4 |