Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.3-alpine3.23-fips-dev, 5.3.3-alpine3.23-fips-dev

Index digest:

sha256:fb105fd7ca44f7b786e50d3749bacf977fc24d6db740db0254eca9b786ae3e5f

Manifest digest:

sha256:c57bd62403d93c72637e9c1c324ed8f908e5a59e7ac531c321c115558f8c5a71

Size

9.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
3
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:6f9c1e40cbcf516a7bd5579521794309ce2b528cf12c2eaa8eb2c540de46c078
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:1a50368783c9a4ecec1e5b0baade6d754698ca654bc9b3e3e7441a1085331716
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:f55381249d7374bd28a74afce6934a8e190365eb52685b7a94fd6c90bcf15024
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:ebbeee3231963374cf603e055e01f7cb0d1c00e5a0c86f0eecf18ed65b28335b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:dbe161dd3503dbea3b022d45ab8708c40e316f684e8b58b13581883aea9c98c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:6344cb0ff563aacec546f6d78294d21c25b79747ce2d443c8ede421f9dca8a23
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:a26996e034a592a709a1f6da910efa9999d999ef8fae31e12d125210475a7921
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:73e146df9af07dc34fedaad2996a95f47a5620cd9150cabbac0f8e72f8586c2f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:112edfac25dd1f33ccd81fc64ae69f22cf96e98b317bd3f4b553cd1ee6b16b08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:08708686fef09720161649255623ff0b475412cd2b70e1d9c03d160747c945a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:04129649ad095a45b0d23c94a9d4c747f99b0aab50bd7b22ea92172b5eb05efb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:06976fe179a68f1ecbf0686ce6d3ad03eb491861cc7188ad2f03a12d97e13762
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:7b739aee24e0ab1ff00a5c5cfc812582ac6c41f8faedb3d09018fc64641a9bb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:d4ede03c4f20ac92f8ecab3cb420a92b2851395183ae4ff41c4e7144a0eb5740
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:f97530bbbd4cd5f872c29ef79fb46a4af9bcfb410c48ef4192bd183a2f3f27a4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:3088a3515387ff4b78a5990e49aa4154120c5d0796c5bc827b814dfbc19e6da7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:902b81d6042bd1c7ccd4ec4c2d9185f71f97656ec0f4f4f6f74bd639dd69b051