Sign inSign up
Bash

dhi.io/bash

Bash 5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.2-debian-dev, 5.2-debian13-dev, 5.2-dev, 5.2.37-debian-dev, 5.2.37-debian13-dev, 5.2.37-dev

Index digest:

sha256:462849f92faece55004e9f78f896a5e6aa988fc4cba866437d676fadae5cc194

Manifest digest:

sha256:9c21c42d6c825fe7ea16318b851e9a7255bd7d471d674dc5b03d6f1798af67e7

Size

30.26 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:ce94f2f99d6045d9c338af096c4f2faafdc7b7ab40c52edbbdb4643453e71d4b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:be805daade8190f867fe48d87182d157fbee2809116571bbc4af356d2f5fae4c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:1ae4cf5fa4a8fb5c2f96b9a12b983b693d54bc8792812e9310fea18de3a00da0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:2efd90b8c06ded062b43b71dbbf32e8333336dfc5a0e62810594efeaffa4d415
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:0e936ce8fd28ee589fe0d108aca622781883d78f93b7e825720d7418cd313283
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:9d6de23af7613165178e309935e978e6f4be119109b582fbe5268832aaca22e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:75c7fdeed31619607e007dbc9b5a394cec6ce45f47df25dcff39f6845ce06ea7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:4231d8ccc18032b5b82c11397647839fcaf99002d2f6ef54b4bc35c2c3372bb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:db3e870c7f4992adfdb5a375bccf969d073f55b4816b49a01bc33a9cf43f3bbd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:e940f055e448af4fa087679265025142ab38b1883564cb8eb576e3dbf167d659
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:42d94d950e9a2632be39dc4b3b27f43ad33e7eab17346c13bd1338f120d6d147
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:9a81144e4da59367a1293b0c555462992263046d818221b86f8bbb100601f115
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:8fe42de24ce790b15080e64d07b4900367d4524c8e6a50abb5e0ba5841c3ae34
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:37a366b2cdc538ec2b6a979f50310b2f19a918b951469a3592e377a2802d5f45
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:f8a1c51a31ced28e5ee60a655c71ec959fbe629e41e0cd1567daa3f769339104