Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.3-alpine3.23-fips-dev, 5.3.3-alpine3.23-fips-dev

Index digest:

sha256:21e0fafb61155537cd63997216d29344f6f7237b34e6acbe0e121012cbd39fda

Manifest digest:

sha256:4456e2d7d7efde19279346fa7c2a10cc782e86d33ee0cf2f64d14ef8018abf36

Size

9.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:6d900bee43cb205288e98c99c3900a00be9db75df1b51e870efbaa36b4151535
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:f71c6f01c265178e4eccfe1742c42b72969f9f7d3e8bed242521a21b2d925ca2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:124a4d828b1d723d80155fda9b96eef486307f0d20646c053997c7bd9d23c1a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:c5bbc96ad6cdad667732be59de977dd2ef9a0a9aeb979c421fed539e1d4fec9c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:f7f62c1f46edc47afef7ca85f4102a3372fdae01a9859f733dbc023421846f7f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:1742f1b130b87d48fb94a64743d09bd43e7e41f292c74c523d7343dd6c0f73c6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:9d087301ed92b8d81867db60be630eca81e2a45a90f3c9107dae82e58a844237
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:63d04805c8bff4320b9d9a2aecfa1d59d750e8be7566dcdf29b03d1430063825
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:c9df01e1d00ba1ef158843820a765b3e64e9a35d365729a141d367549477a577
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:38fe9d45f90b76a26797ddcc9635b745c84eddf1ce3566e6690ac498185dc40d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:d2b41d6a2fb23d534a6a5cf562f30071959af1e5d4b2cc00abfae0d43836d8d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:d176d2faa97b91a29170190e22ba8b3f4a0082454fb761b646f535e3393d2cd5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:b24d293295c4a5425086b7963b36130709b73c8563b25bab53b67b1470cc5d8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:3d15e012da090d04c4813960f0f6f725ce7b709da7275ec5f370d83ef694f712
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:c1b4749d3329ece78de6468cfc340ba88b27d02699e8a7e9f466ecd44a2a5cb3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:170596e71158f574c5eefba5883c2611e325bee47ec5b54f65387e9bc90a1ca4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:93ac847851c27a7266b89e457f5bcac0da5ff9c3d2f4a670cc7fb9c5dad16e45