Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.2, 5.2-debian, 5.2-debian13, 5.2.37, 5.2.37-debian, 5.2.37-debian13

Index digest:

sha256:4c20bfc9afc53a1d3fcb8436e1e1b10bc03c3ad51db07da15b6a153eb6295d2f

Manifest digest:

sha256:58c69d376d72d069509b112c9a543585e7545fe19a6d11e5167e8ced0c9086df

Size

19.71 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:49f2a312153b10d11ebba3f88c8dad4be62796785f2b56a4a18e27f3ad3b1317
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:0444c6446bb3fdb6da6db35ff7185ace3961327672e16a54ad9603c020913e22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:59921b7d4fe63e1a4678613040669463c8191ae7c2ff66ea59d7f1c625f93b43
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:a23aa0c44252406dcdf222c23e6b973ab3a755993fbcb7e754cd0164e8fad640
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:3d80b4e847c37c1385a95571bb7c9557a8b6151f4759f9193646d7f6a2f0f9c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:5e13d5a2cddc019777ea0073f4b6bad755c87867e0a7d60109795f65f575502f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:64ec8f157d4c9ab1385e0e28f7df467080afdc84eb448fcbbcfec7a49200df22
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:e6bc880c0ce05a4892afb54aacd7f118006bde390fa718b2b9cbb74037e35d7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:5db31098106fbe2523f7727d72f6729582c5d3e4bf26ecec66e3f449181be523
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:4b3d8ffe99431873c3b6979d8ff8793c285fcc650f96250ec6da2f15f4b4a70c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:b7dec060815bae5f09d3e8cff39979910a309953691477d14162053d52e3038d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:24af7169904c9801b0027bcfc0f88e916241bec76ffd738055656dfaa7a2fd25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:1d31897341c75188f719021ee07555e753e59dae76dda5d44d9b2f0f993dd190
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:dfe3fbf0f3cf4e28d7134926d28fbd03e4e3a6d95fd1d3c4c50d217ef6158c1a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:8645e9338bbc85eb8627b14139705bc81df8d34beab0365b504d0c9e92d85b63