dhi.io/curl
8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.14-debian-fips-dev, 8.14-debian13-fips-dev, 8.14-fips-dev, 8.14.1-debian-fips-dev, 8.14.1-debian13-fips-dev, 8.14.1-fips-dev
sha256:6a18a54449a2e8082caed21aa808e3ea8aa4110ad919ecc8d3507ef8073c6237
Manifest digest:sha256:19a96952351bc232a5d5415a7990e2d15a356cfebd0c290638c2f73e54ce618d
Size
34.20 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/curl:8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/curl:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/curl@sha256:b8e1a0a2c9b96ee27afceefadc33b04d804e97a5314635439fb6471eb8f47e90 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/curl@sha256:6b4fd75af562ee168e134785edf6a061f7bfd74af0bdad767fabeabd9487b1a7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/curl@sha256:1c1b33b770e5de4f43068c91c6aa75586ef4b7ba274d691cfb54d4ff575115e0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/curl@sha256:540aebf5597a43b3e0ce6c6e5dcd2f180bb4ee8c2e6efe65c0066a8c3a648339 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/curl@sha256:7e93235e317e20f5e0707c831c42c03f3a7da8e5a38a26c0967d21dd45d6a6a2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/curl@sha256:10fe98c3e9a1b802e10049612af14146cdf491a49993ad25ba083e2c9ba5ba2d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/curl@sha256:831da069d592c4c1f13c9d666c0f1cec3c523a8983f640cd5c2e75ed427d8704 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/curl@sha256:6ea1dbdfc980b59dcef6735962d0e1a278c981d1aad4f2a90e02e493544bbcbf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/curl@sha256:fa5638a01f9578f76387c08d942d7ff613d32ec65d23817ac9e701898850d884 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/curl@sha256:64e1991e4013b0bee444a15bd46dd3abc69594accf6e5a3cae08d9136b0e7548 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/curl@sha256:2747c598ba55863e5fed360a04b9d8c5eb52810cb0311cab7a8de28141713680 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/curl@sha256:612f734a901fd30f7c036f9586e96c5b5a95e0a5852993f465b71f2bad62aa31 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/curl@sha256:833dfd29afd3651eb70f7618ace4d31102231bdcfda0b8341ac0712529c60cf4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/curl@sha256:d4395d3d6381224a1f76965314e77562d3d90ba36b03357891da285d27d09f98 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/curl@sha256:ce1a3e5fe3026813fd57aa9ccdf843fca46b1b115dd093b8a31288e8ae6e99f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/curl@sha256:30797cc8880e620f6741cc69bf95933de6d18a5769f144fb056074f0c572162b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/curl@sha256:a87d97ee080e1dcf4f34f453bbd2db2d80479313b0a3b89048d0341b8d050fbd |