dhi.io/curl
8-debian-fips, 8-debian13-fips, 8-fips, 8.14-debian-fips, 8.14-debian13-fips, 8.14-fips, 8.14.1-debian-fips, 8.14.1-debian13-fips, 8.14.1-fips
sha256:07b7f217d172758438dfc88a4573c7e166467cb86fed76be19f0edf66c095321
Manifest digest:sha256:f908e4681abff9a4766cf09e70f5618e4d88bd6d4da15e578fe388b8ab184e6d
Size
20.71 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/curl:8-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/curl:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/curl@sha256:e6ab33649c66706cfb65b938652975dceca454fc1dd8364d56e9b478fa32c63a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/curl@sha256:1b2e968e0f1bcbc0a99bdc66c9f025219312309cb2d4e273cff1ed5b50eee85d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/curl@sha256:02dbed73131eab746436513ced6b0f030b2ea222c62a143f026e788a42350579 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/curl@sha256:8ee60c663f8576b56370d72d421f06334c742a4a76994a290e3329b0ea7d1369 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/curl@sha256:8265f2b8bf37abe620fedf8c738d0f6baf387c58ede0d95c02c07815cb55ae01 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/curl@sha256:fab1decc6533170d28bf6db8df474ad99deaa4f648f0628f0d8e29d0eb662f40 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/curl@sha256:552e10a264268e7ab073acd1dc35cc42d72fa4a8f87024872024f5d5f0f168ce |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/curl@sha256:abf7ce3374d2986da94b863d117f57d46f530e240969588e34efec33be1b8295 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/curl@sha256:9523ec65f7a1ee9efda89596c321636e56928e7ca0cabcbbdb1d34e3b8acc2b0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/curl@sha256:8d82032c6cf3d7b4e61fc842a0e2e37ea46ae8c4068f4f1d5a87d30910b7821b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/curl@sha256:c6bc1185a1eb85ab85f9db9fad9d947825b7da2c0fc680f87b5a17786141b97a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/curl@sha256:44437e95c7e6312c669672cab9c53a6c2956f9f857a12be0a1afbca6f6db0a5f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/curl@sha256:13fcdec0c45124c82a4800f96f640a1dc46c5552cf5e3d2e66a4ea6736237a88 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/curl@sha256:02f613a71f57e0f9c6602bde6651ca068faa08c146ccead4e222e4627bb46e6e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/curl@sha256:0ff3647154695aabcbed999903e0a25a0e98f4eff226df9c700c9b7a1cea45ce |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/curl@sha256:85ccb007061aa1d319dc2b8abfb0ada9c9db66d257d155d9a5929db0e63bd272 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/curl@sha256:623ebca15db53ff679ac494535637de983b599fe8358da825f547d1a880b6f8e |