Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.2-debian-fips-dev, 5.2-debian13-fips-dev, 5.2-fips-dev, 5.2.37-debian-fips-dev, 5.2.37-debian13-fips-dev, 5.2.37-fips-dev

Index digest:

sha256:f530a664e8bf75061ca5929d36e97d32ed0823bc18f7f621681ce6debb55d5a6

Manifest digest:

sha256:5468d7fdf8665919f03452858ca91cc3d4a1c8382207b991e79558db1fc77949

Size

31.01 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:c5ba0b3024df65cebfdaaca55db328b8573c06dbe0cd0ea2907f63da4ba4a9d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:b03fa700d7537153d22129dc8719ce8c78ab0054eee892166610f6cdf6fc5a31
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:3d52caed23ddb919c501e3ae8b3c82dc6e97e0c8062f25d96248fb5fde891999
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:66fdee24b6458fceea48bc0cd1c020a17b197b5fc92fa53a0640bc8a0da56697
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:0489a69c3f025ddf82f3c6552a944d10c67646f8eeddb1c00613d996a0908481
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:3e08a27f90d1ebfca4a765e5111b8e933f2aa03c23df34510cc7aa971b068991
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:d0273a614700de34c9d4a31409cad2ae6aff5aa4036c98658c732122ecb07631
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:b7693a4d8696398cf8295db0f5854c8b0661cdb6aa024fe7af45b6fde6354057
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:d2623b17efd19faba38dfcfe02d0b70088494a81142c28c35de2c59ca815ab2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:132f7860183764871202a301ab19f22ed4f9297244c1fb4499154ef794344f08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:d9f4394e3d93c48cb98be954f683295e111b0642d7ca912bfbc2e9a681cb270c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:91ca816701256e4719004eabb978de5556678ff1eefda4f5160a7cffd78cd21a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:dbf12cc77d01aa043462649b999aa2fc20a2d2bad4f8f7cac18f24f54cad9d8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:69192231a49bc8450076d53f6d6dbe51b52990359b39a80cc97982cfb405da21
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:2bf803a49a1e98ccce1a7f2f16a68c0eaa32fee47b112fafa33e8902ccbec6ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:04a203cf212bb4563f7141b01281eea05a28ec4b28bdb4889a9292b4b851659c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:d364bf93d700065002aca1d90be57f785829cde6d66d139e0195ff4ecf1e3148