Sign inSign up
BATS

dhi.io/bats

BATS 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.14-alpine, 1.14-alpine3.24, 1.14.0-alpine, 1.14.0-alpine3.24

Index digest:

sha256:bd341a37eef0e132994799e43205c1bda9da90f57e187ae1fb1eed192cf74423

Manifest digest:

sha256:af7c2d646b67efff5a7b078823824dc35da4d51c24f7780a73a92565a71aec8d

Size

14.39 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bats:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bats:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bats@sha256:d050e5d865909218680eed447bc5c69b1d5ecf1763888ee6c32b01aedb52f5a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bats@sha256:3ad65e64748da884a570f51403c85df9145ee975aa683e755f243af55604aa0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bats@sha256:d02e676d0e58939aa16d072f03f2db50578067a2f4bccc7fcef7a7aee578102a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bats@sha256:5a52b3171bddad0dd7724ac4947c19e8d2b2bcd6c76772c49451c2c3f0dc1d1e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bats@sha256:85cbd78ac396b2f7ddea552515c28fc39e8a2c2c251b552e1d79d2d4311a2b33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bats@sha256:78560e749fddc8de94db11565fe8e534a71e41af44c8f2cc85c0ef77a46bf07d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bats@sha256:9727719de9821adb51cfbdf8fde462ed25f1a482aa71391f5e067f600b069f04
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bats@sha256:5ddec2a5e2fe7f2b619a21b56ae7c234430018bd4436cdd305360ec09245773f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bats@sha256:d4e3f36cafefe7027e856b1ed98a7a8b8d2b8472918748289e0b3cf88d5aede6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bats@sha256:d82da2ab93bdf950f8e47878817e1fc0bbe16f3cf8368359cadff814c1517f02
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bats@sha256:66145551a069b74854e7137ebadd7ad23f273862811fa51e3140abae6e5c1b8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bats@sha256:ccc4358585a05218202b43d878f3a4ca2171e98dbc10c5a30d416b9d1d08fd89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bats@sha256:7cca086f933d65d659444197d3caaea9890f39ff42ae22d82cc1025b1b4abdee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bats@sha256:51c0cad8d3812894dcd6f580c2d408694d400e5b16526a798c4fd0eae8a6b59d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bats@sha256:c23c6fd4c51f4c5fb29a8cce3f30a18d0e83599f26ef737e05d8c3616e72223a