dhi.io/bash
5-alpine3.23-dev, 5.3-alpine3.23-dev, 5.3.3-alpine3.23-dev
sha256:95d6b2a20836107462b59e61d925315e537470cb6b1fd14a4c88c093b99b8b2b
Manifest digest:sha256:2c388298e5d39dd03d933d872862fbff23f8ebfdfb7dad7574b0088c8ce7e6a5
Size
8.27 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bash:5-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bash:5-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bash@sha256:2f61fc7c3a3a15a86269cf2d054eb106289525e2e9f5811aa94aa741a1fde6b2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bash@sha256:173974198dce887b44ef946b71bb26892503a99982a3cbb5913c7db88c30a688 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bash@sha256:63efbf798a48e52856d4e314d789bec7b487fb0aa981e9dfec04133179158820 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bash@sha256:e5e6bf0dc92e8e2bc965464c4d5028fc56c9b14d8ab222e0e96c2c61e6142225 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/bash@sha256:4ff44162fdc41bbd4e0245366d279ad75d9c568085727623f1872d0773f14df5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bash@sha256:a1146ceacb8ab9c1576c6285f911dcf4f8992671ee5ae363f42a22f5e62e45a8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bash@sha256:f8752f9b30ee94881ca9d5d0cbc53670e65498226613f8afb750df7ae0856a27 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bash@sha256:3df3909b5f28c7871dc96babba980599848766aa00f503bc1361dabe38df4cf8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bash@sha256:5b0cd7949f9b77c32a927726a18d7002745bdef215622efeb79827b192b8d1fd |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bash@sha256:55db38c6918ac38e1239f3f9ef347d68f048120ac676ff985c06a64968764202 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bash@sha256:a91b99ba1e3601b021b0eebbf5f831c86e94e477d18894c651555ce4d449d78e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bash@sha256:ac6ec4085d0bc541f8ed671b92350c48bfa453c681d0a19296cad8bb7c9d98b5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bash@sha256:7fd9a35915c02aa17d50ab3e8f1244f48ee76ba3f07371ae00a8b1181c96983d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bash@sha256:02fc3b481e68f72641471dd9c0561291da79e1ff3d014bbb7923ece2c2b67cff |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bash@sha256:58f782618ad511eb08e075764564b6c8f7ab86041d0b460661b15770381d9127 |