dhi.io/bash
5-alpine3.23-fips-dev, 5.3-alpine3.23-fips-dev, 5.3.3-alpine3.23-fips-dev
sha256:21e0fafb61155537cd63997216d29344f6f7237b34e6acbe0e121012cbd39fda
Manifest digest:sha256:4456e2d7d7efde19279346fa7c2a10cc782e86d33ee0cf2f64d14ef8018abf36
Size
9.42 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bash:5-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bash:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bash@sha256:6d900bee43cb205288e98c99c3900a00be9db75df1b51e870efbaa36b4151535 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bash@sha256:f71c6f01c265178e4eccfe1742c42b72969f9f7d3e8bed242521a21b2d925ca2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/bash@sha256:124a4d828b1d723d80155fda9b96eef486307f0d20646c053997c7bd9d23c1a9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bash@sha256:c5bbc96ad6cdad667732be59de977dd2ef9a0a9aeb979c421fed539e1d4fec9c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/bash@sha256:f7f62c1f46edc47afef7ca85f4102a3372fdae01a9859f733dbc023421846f7f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bash@sha256:1742f1b130b87d48fb94a64743d09bd43e7e41f292c74c523d7343dd6c0f73c6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/bash@sha256:9d087301ed92b8d81867db60be630eca81e2a45a90f3c9107dae82e58a844237 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bash@sha256:63d04805c8bff4320b9d9a2aecfa1d59d750e8be7566dcdf29b03d1430063825 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bash@sha256:c9df01e1d00ba1ef158843820a765b3e64e9a35d365729a141d367549477a577 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bash@sha256:38fe9d45f90b76a26797ddcc9635b745c84eddf1ce3566e6690ac498185dc40d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bash@sha256:d2b41d6a2fb23d534a6a5cf562f30071959af1e5d4b2cc00abfae0d43836d8d9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bash@sha256:d176d2faa97b91a29170190e22ba8b3f4a0082454fb761b646f535e3393d2cd5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bash@sha256:b24d293295c4a5425086b7963b36130709b73c8563b25bab53b67b1470cc5d8f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bash@sha256:3d15e012da090d04c4813960f0f6f725ce7b709da7275ec5f370d83ef694f712 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bash@sha256:c1b4749d3329ece78de6468cfc340ba88b27d02699e8a7e9f466ecd44a2a5cb3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bash@sha256:170596e71158f574c5eefba5883c2611e325bee47ec5b54f65387e9bc90a1ca4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bash@sha256:93ac847851c27a7266b89e457f5bcac0da5ff9c3d2f4a670cc7fb9c5dad16e45 |