Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23, 5.3-alpine3.23, 5.3.3-alpine3.23

Index digest:

sha256:6222dd4024659ed0b59bddaefa2e1a6e1e9a92e2a5c764cbd594157bce9d452b

Manifest digest:

sha256:8aac26bb61a5c19c9d16c5807a4e5c4f95c23fd1d9523786e02db01e8f706d76

Size

8.10 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:adf6eaab66ad8750b1b4101969f4aa5abd2ae516eb94798741f6404bdf75e292
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:6e3bdcdac62524ca901525bd6bc6276426e2b61972f2a6eeabf323ec95250a58
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:acd2d45d98413b4deec374000e596c1fd6c66e128203d4aa9c37d8f03752dcf8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:0eb9023c842c5c4c0e18d0c596e0168df5d6b8381f412c84012553069e4b0d27
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:4753583b48557b27dd0b644eb94c0bac17930952207be4cf198f61b487158b24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:4892ac85bb70f806db472810739a1a73b40ece3a8689ecfd349788aadc097bae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:1ba7dbc4f3236020758ab5f2a7d3b144d3ca352a75ab50eb05df1583671ad61e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:228d620b35f14e3acec759a1001672bc3cf57f7a959cacfd1d3c40c6f9b4c7b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:df10ad24e74d8211f8cd29a2dcd2dcf77a32b3ffb01d79809c5abbbef3c05e3d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:73cc619fa63f15c75643088c4e43454eafa47bf22f0055e8254f1cf9279ee112
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:d5d899f1dd8dcb447e844fdbca8d45b5b76c1273ed5469db7dc5aa4fa06d7020
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:3e9dc6cb58b56dae2f113353c49e424f3c9b356a09508939ebf751c5e5b95994
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:99c1a39289c4caf18170ef8093063aa0794140f6d07e4c553888d9e7dd420eb9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:14dbb88b5850cedb34a01c2ddbe0d6368871992d787ebc0cfdb2d2791bb5f89f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:af55b69235d98166ea1a2a6a341c16edf8aad3692b1a21d81334f0eef37f56db