Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.2, 5.2-debian, 5.2-debian13, 5.2.37, 5.2.37-debian, 5.2.37-debian13

Index digest:

sha256:3d6ff50706cfe3ec56722ec5de67be7280619b43eff997749b8bfd44eab658ae

Manifest digest:

sha256:a00e09cbc27c13aa12dd0151ac705a598da75f20cd8f2a3a1c8ba47b9c8383f2

Size

19.71 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:23c2c0f4e770baac81304a5444f0fb14ca8889286c113b01967e05e6b978ab5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:f3ca7e3d2febaf1be01327e1fc15cdc894327481e5046f1e86eba5ad36ec2bae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:890df757011d9024f932e3e8a662033a8cfeee5be6e22f15df30efd14db2acd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:329024d0f91ae0c2b855a124eaa49faf2e06075e37facd26c5a05a2754239920
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:befac9fd034c2a2dbd8e5a24a4d632d5b20590c822c7e1de36049873299486da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:afc9b2bbaf2cb957fb02d037ef55b79db17867146976300c8ab6e80f8b45c23d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:d3f4c366146f63b1ac240573508ee72bf41afaed0bb639e056f34529d816ae0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:7b400b6ceedd537e0bd135889e32a22fbb4dc58616d661ff7e71e53d3be9b65f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:51e038e60e58c065fe2a9bf0faf438d8599c407d1a42b611f2d82c1d9229c5f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:cde93a63b4ceb308c7a1d97a2ef090c20b31b9b026c4799390d9a40245041c2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:ce4754e241123965a786aa7956626503415788c2a99c17025600d397eae5d4bb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:5a55ca0384efaddc0999c15e7cc03944005ca29cf32c4df47c830e4edbe234c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:3f06a5d933fa47e8f3bf322ae8d3fe1a1e9e41623052203ad791ae78c49a0e13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:f518e292f6d4a2dfc23da6a84fb9ed70f7268d08c339de21ba5d47b60a392af3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:6b66abfad2f1576109dc65591c259eb74c431feaa7dbf9d52bac83c315d3fe37