Sign inSign up
curl

dhi.io/curl

Curl 8.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.14-debian-fips, 8.14-debian13-fips, 8.14-fips, 8.14.1-debian-fips, 8.14.1-debian13-fips, 8.14.1-fips

Index digest:

sha256:2c0529e862088f5ee0c7fa1fdaa63d089e2cb5d9e7a7b7e1281d3867b3068d26

Manifest digest:

sha256:a4dd028749694cd96b6e8ec7c700166cafda15fbedef2852d6b80e43e844f5c1

Size

20.71 MB

Last pushed

3 days ago

Vulnerabilities

1
2
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:16f358b5c4e1d64692ad664d036d1e6b274ed13856898a6fdbeebca7dd6aa30b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:4c92f78c3d93798caf1ca599d7a63f25ec7f8bae3c134face34e85992d37b1b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/curl@sha256:7ac5e8ecc8a220f92bed2d374b34c2172dcd9b935553a1b88ee84270a53e5dcc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:45db23208904ecb94f87df4d33fdf09caa014e7d8c48f11d62fc30fbd3bce030
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/curl@sha256:987ae45b3aef050beddcb147d60333c821d70f3bdbca97c9f5a37b04d9240ea9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:70c614265e6617d02547de1c8e271163fb182c716a2216324f7891f3f7d732d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/curl@sha256:9a7eceb6e28ba20001ce39b6903afd02cb8320c05346d4e7d30546eaf06d2c06
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:6f1addd3ad95a4997776c1d5972b1bef3281506ab8d46c2df41f97ff3e654298
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:2dd360442aafcaa7b1f5de2146973b63206d623a9f06fb00c329455c5cb89676
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:284afb2664bdefba0c643a1cfc83c624e3a4dca04c759020fac9c88dd2aee9a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:2c6f78c6e5e64c8746ee14d8a9bc5523161b8ef6b88eb2ce5e74f48acb6619eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:c68d56ed2640383825ace0e584c63f2e019faf9fa1bf047a9ee16bbf7de7ff12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:9531b06b7068bbc64c8d116334658db925d0f880f207bd7bb6447eb111089f34
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:ef25e1985700adb08dbf412c779ef626fda1e5d196e90a9c8c093f9ed5a14d10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:d29cbed63328ec40add2a1c0fd3daadd12d987a7af1e3a22688cd26d3db8aa65
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:63b8ea12b0d4a3f72e21cc196079190ea353a5713948ab23b49c18c47eaf8beb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:9077520560c8eb9435af276a09cd94578c694a3b732fb79e39698baa343106d2