Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.3-alpine3.23-fips, 5.3.3-alpine3.23-fips

Index digest:

sha256:78dd82575640de8f3f888a297e3c4bc8926b5484b3f8e5a16028c442f1c03021

Manifest digest:

sha256:381815c1be274c70cbfc9176b9b36ad4f012395a8cde82cbcd3c0970ea8f01f2

Size

9.25 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:beada9dbd3b7e5e8f8734dc12da3d9ee85df9f5aa34f263286d643310e9ac4ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:5c193c5cd19d8929db08c0bef349f9a097b9fa5de7b681b0a7e786526f5ba365
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:f830035d202624d52e8778b27478d82ebcf6f84cc0af924287adc5a6bce8941c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:4b00c8a31b98e4a2259ef3d11c4d05e498a4b095bdfc702d261b0bc5f185e0cb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:1dd97de78072b66b2b8f3cda5cee25af0cb1cc31311eadfc74daa47d2feb61e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:9cd92a7191f8cf8cfba4d47b481ff38d0ef67e0a0f86d3d0b8cf1ba2b554090b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:51cabda387015c0ad5bab630874d206131d55dcd4d339de7fbe99218c9e061c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:b522d36c3747f0f8214c3f6ff21c458d32b480165cc0a7ff0dedfa83a1b5eb20
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:06bb90591e7e020f34fc74378084ec1ab419df43d361283ed3d0dc783575816a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:887d1e0f120a1709748d688b38a1c4b964545f63ab9a8419ffb83beb866ba959
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:83b4ee7d4410942d9e147f0928daf0485496000e5d033b91346ea384f58a698f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:3122a31ef88ad3078d6f7257fc78881b1f57e247f5e444d158983dc179756201
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:0a3977c405020b6e1aa9c8aabfd75dea5fa7ed1be55df95343ac08c623afafdd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:5f309594067fb518da3fac9b8d1b4d8f9d642cb35af0ae80e3bebca324e59a47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:7d5a7fcfda3565908ec0919114ca0479559f7d9b47398b9c7d480f356170be5c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:3548ad46c35ac3f54bf8875f29efc8b61204560c311842e50386d01ce42e20da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:5d982cbac3f89171a6771e5db2fdd4178ad7e4abae723007c64c130f62bc0bfd