Sign inSign up
curl

dhi.io/curl

Curl 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.14-debian-fips-dev, 8.14-debian13-fips-dev, 8.14-fips-dev, 8.14.1-debian-fips-dev, 8.14.1-debian13-fips-dev, 8.14.1-fips-dev

Index digest:

sha256:91daf3b4e5b16dbd4310fe9803537030871eb53f5a67f545f98e32a1d80f7fb5

Manifest digest:

sha256:7f8e26e807b3c663f97f10fa8aba597d827a84d1235fdea0f00652024513ae12

Size

30.94 MB

Last pushed

24 hours ago

Vulnerabilities

0
2
1
20
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:a4c7199aa6f18cc5e3164afd6f2c145ec07b9a5818badbabca0703c48e116bce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:e989311b361442aa54c31f1a07b77778fdf6d3e9f9ea8a4934295cfeabddd790
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/curl@sha256:1f2cf8595ada6fc101058cd169eb6b5cec11b78f92ac97840552bbfffa4fd309
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:40d61ae2ae1a800274c33cd38f49108c5d9979ab8d429ec81af926befb9fbe40
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/curl@sha256:ecfdb6d1e1e28b762704e06b013cf81144bed4af262faccdc9618eedfb35e1c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:7bda4bcf20ec885769f7ccfc5ae69b88a1afcc4648f14752fcf2664f74d81d32
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/curl@sha256:bed017af54d6e76d7e345cf4f43f1c6526805f7aee97a455ad7122ac048f15be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:a867d986aa3dd8af2aab1222324b63bcbb8c0af550995ac2a6eccc17e556b8a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:47c557a1ef842bd0e7dd10ae35e3bcaefe940d7c3e73c3ad54315439f7ebf9b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:1df785286b56b2947d69ae05387213e93cf155c5c50d8f380f8f46857e0b0796
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:4a5107fc8bbea75a91bcf7fc52a553df6fb5df6680ee3343882131936b33ac43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:488fadbc6e5ed97ac6cbf5fada37aed018959e4d2c1d79f03381c9647ba5d3e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:a0431eb55300d20b2d765b5a8b7b052b88ac882182296821e701d7fe471ae8ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:610f7148df2739d4e7f2e3ab711973fdd7fcb46d29b8f8a1cdf43613f67aee7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:f2b85a4844ef92d95881fda242b4373618c5276614875853ba960f137b60c300
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:1faa23d77180516d3c853b2fca68a2f4e725ed67354b9b320153308a427cb645
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:343efeb3d92042f3c68668fd5d39b4bdce090d465e6d48b69074bbb484e3ecbc