Sign inSign up
curl

dhi.io/curl

Curl 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.14-debian-fips-dev, 8.14-debian13-fips-dev, 8.14-fips-dev, 8.14.1-debian-fips-dev, 8.14.1-debian13-fips-dev, 8.14.1-fips-dev

Index digest:

sha256:4f8d7411886428e6e3f018c01a0f1469b69dbf9aa57cdd341257fed8c513fa4a

Manifest digest:

sha256:d21c937b00f255d3b66eb4adbd5e8e15fd4341851b7e073ff04cd16fe938ffcf

Size

34.20 MB

Last pushed

17 hours ago

Vulnerabilities

1
2
0
20
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/curl:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/curl:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/curl@sha256:b016518277cdd2940128981615b635de4abe9ba424dbe9971d32ce478dd9cda6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/curl@sha256:2c407071b630835151d09b0b44a878ab072eade75157c76e2d08313df0f8472b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/curl@sha256:14a37bd159a0a790043872099a70f8740388c97ff5e11fdc22a671866cacb379
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/curl@sha256:fd0413c0c16215215b51f5aa460691f0cb49a93998b5cac958251a7e9fe565a8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/curl@sha256:005aa62ce3423f9432a631bb0ab09c69cd9686b41340f8e8de22db6b478a1b92
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/curl@sha256:f9e486320852c8ce4074411e1c823c540da6b212176b268ca2a804a5db03995a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/curl@sha256:91c066c7aa84722fa15ce4a45cbfebe26635ecbdb740d159f079f6b5d7bd2592
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/curl@sha256:daea2a626e00419dc0d99f65dae94c915541e81614d73a9c76570e9ebc23c23a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/curl@sha256:a00b56aa0ce4311d865ea95c7904ef267d5c3b736216a4ae3cc75935395d40c0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/curl@sha256:257f42a4265269d109e6ad7b919c49b59450fe8a7dd1b9756d9ca1f31acb9e00
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/curl@sha256:38c95cd71f134d154d93b6ddd5af1865700473e2164170c590b275c446248110
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/curl@sha256:338f341338ded68205d5cb198228e7b9a395bc38009686537c205c90e10ab287
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/curl@sha256:44b6503b6a360397e0d1fc07c5bbde0f870507168eafa65f2b9921d94c44cc57
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/curl@sha256:ebab90195df17e193fcf8bf37f8d3f66b844ad751fc8da6101a350f0fe073cfa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/curl@sha256:4a357d272505d125a04643595d9a80ab413158774c8ae1fa7da70f7cda0c0e6b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/curl@sha256:ded90a84dd5115b51ce10453d7c12b88ebb3f12861b9d12d68d042ce77bb20f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/curl@sha256:c1c9fc50a16b3163a96e759d1c120dcfc77e997f00d385aac0f88a05e3f3039e