Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5-alpine-fips-dev, 5-alpine3.24-fips-dev, 5.3-alpine-fips-dev, 5.3-alpine3.24-fips-dev, 5.3.9-alpine-fips-dev, 5.3.9-alpine3.24-fips-dev

Index digest:

sha256:1a76123aaf023830621c5c9cb2d75f986f3d0bc52126d50dc1a6d397d84ad5c6

Manifest digest:

sha256:1d8766ac5ec00de9faa8ef689ef0ea6562955c3e11de2c11d8bbe48726aeff5f

Size

9.48 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
2
0
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:f87cf6e35fe79445b95265dea99213d34b1a6d67fb40f27d7bcb7a4e535b385b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:c3d31b1f07a198abc053cbe0840ac56c99ced7f5026ba558298f9226b8813b44
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:44bb830d6acb5ee6daa5ee08d5c0769116243013d83fca905b35026e2e8d84b9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:acd052bde1128f98947e66220bfbd1882b364669ebeb254d92d15ee56b51d418
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:2d79df87b604143633b00b77e77c4837ae67d5f84be0f5c2f96bb3f91dd966cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:b2586d7be321d3388b74c6713c2fd113b135c2a776832256c3ae760721b9067e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:d2d88930dc3e829d9bb3b3fc5876c9df5c9cc8b12b7e4b75fa990a5e4abf9dc5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:8567bd9c6bdd2e40df3ce9fc953ac7a4bbecaab0a4d2b22773511e95aaa2e2b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:ed4a37bf2c93b45021dbabe44bfb84f2268213f0e2e2f1ca7f54b2154782bc6d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:cd1976f370ba18010d57323dc18a1bb5b873e9506435907205c4808580b587df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:d1b50a64aa936da77dbca30083baee872c1abc9e6e9f614903394d366d4891b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:1d119db8308cf2c23b2421b849e672124aa71ae3dd8d8e1be309d7796418760d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:f09ec57802d524d3472ecb0147aa231d3abf6f0e7ec3f5c23ec53bdf892bb618
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:8e7ad2848829387ac13b2d69f37c1664bad0115642f510917801681a1f7f04cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:35ac14bc38815d0c896125d1f7bbcf1b83aafceeb38dbc00a2d9d989b6b2bc9f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:14e1f316b4ad18da31884a181009240334ee7cef3e2723ce1388f99cf9983899
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:5de87a22e3dcdb2e8cf7ffd4b1b49452607916271407ee64f5b156a8438a0d81