Sign inSign up
Bash

dhi.io/bash

Bash 5.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

5-alpine-dev, 5-alpine3.24-dev, 5.3-alpine-dev, 5.3-alpine3.24-dev, 5.3.9-alpine-dev, 5.3.9-alpine3.24-dev

Index digest:

sha256:1b8dea4e208ca3c3cfc02840304c1297525e69953f7f66a57a9bf42df72a6bb5

Manifest digest:

sha256:800bd83b2abb68c773ef02b5a568de6545c9227bbfa7df5e7d5beff9a64298b3

Size

8.33 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
2
0
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:564da88f87ceb4799cbc776fae41a19afdbcebac8ac96485515f36f470f9cf0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:d2e5d48b9611aa1a7150e40918271438ae47fda7a78004f9e7edfc7b5f38a153
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:3a191d9e887d5ea6c6cc4cf1079e01b7cf8c48e2904f4cf60ae6cf739b3acde7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:365cdbf3415da092fcb599e2d42b9e097d5567792bb4188ba91be5ab5074f3b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:904e0c217ee39bf46531f5f5f047a90552d05ccd0ae4cc8eb1a7f6dec8460889
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:a90ad7e7d58851d58536de4b9a189d16a1a99872ddc18a8794b294d24feb03a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:4ece24b4d3d8e5eda2a4f0440a9da6d416b47e29923cc1edc307419ea1b1165e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:7a98db717d0012ffeb2c890fca97153fe1bcfa89fb793b8a36f93747fa4df08a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:c21860af596547ddd041bcdf08adde5602a430c08ce62d1fc307d141913b4298
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:1f39245806fc6b1a7c49685e2dfb49c94a45601ab61f7c435331f3e903c54294
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:d24783c5f3c9d1fc70941ac0bc7c730cceaa35b192c7909f29db23d3fd82845a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:cb72ffec91a28ffbbad26e1acba396647039fc955e0ba058c09b9d9ea6f9309d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:193ee03b5f152e4e1f159840dd47a993707dacfaca6f2749e4b13f745d61c553
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:d719ff2e5d4157671d7bfe114c102e8efa8449e5eb399db3e2b9f6b6e9ccb763
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:9bb417aa811ba85de0a7f8bcec6304e01fd5f0355b9d23370fbc635166393793