Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23, 5.3-alpine3.23, 5.3.3-alpine3.23

Index digest:

sha256:f84eff25d012d84a884f84ba7e5471d3c707427e68a5b49d4cb6a5fac268ef9f

Manifest digest:

sha256:0a6349610c781e96cf400ea6f49a5b0ac7325b1e105cd9ead76352128bb8ba36

Size

8.10 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:b6435984f57ca878f556066ea8ad676ee40a522e270dbe2a2e97b6516e6c2b1e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:13e41e2be68c025ba8071345b04f8b95b994f3cc5ecd66b45796fb938de39ac5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:2b3d4b21f7ca7f547aafb25fc0153b4bc3cf4dc18721337a67c98674e37cf457
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:de83d06371cd54e746f5adb341de45841c9b7738cb4fc15545547ebcc8333d92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:9324a774e4c17587d7ab83c678efd437bf62cc569a178f3fc4477ac1f9218820
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:ba22512f70892a6035480eb0b6ff5606ca82a5dcea936225f8db2973aaee547c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:1be6d72cbb7db4551f20e5b292103e8b816b7f0c8cb9c2bd64142c660431dd4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:4f63efa7a601fc9654be370b4a456572dea773f76c926c987005f7761ebc5989
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:4a9e7337ec714ffd8709e662dbc1b7de74e4a1172766bc66385b45d172db0140
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:35649d9ff4bac62687225103941f2a7516a0cbab3ff7aaaf7d95b5d14ff05e03
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:d927bfcd6fe1272f7ccfd6eebcec21c168cdfdf1e22fc1c63c0364afea52beb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:f76af6264501c19bb2085dd96034016668a7ce7a47f3f7f09b2b0dde06283286
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:152a532d9c1858a49e53b3633e6020fececd9834c24905521702d5af9944d6b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:388e7a075d153305babad9f4cdbfd98406b9d4401ce0536ede55bbb9c8cc42ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:b489bdc8a3f781731db4cade77b9c4431bae539f93f35e3042e03e11a6e25305