Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5-alpine-fips, 5-alpine3.24-fips, 5.3-alpine-fips, 5.3-alpine3.24-fips, 5.3.9-alpine-fips, 5.3.9-alpine3.24-fips

Index digest:

sha256:cb89df51440f71221515cd1d445fb287796fbfe9c5c16500c73c0d0dcfd6299c

Manifest digest:

sha256:59ef71b8421beb47dd1e1d5da3a6ada1277772367707b911f47d6615e6f2db36

Size

9.31 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:4027b5a0a3a38e9ddeca9da475df306e167060c5a528b30e7e1aa24a60953bf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:3d5f0cf2cc4ce67b4864a1714da3c5610a05fa441bde9ce00d7e7766249126a2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:94a20e9e43adf5dddb6c4c37ed4832342f9ed2454fbf25c9e905158d5c91af74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:837318a5d2498dc779d2e115adef027e6a777dd7496c62c395833c414b23c0c7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:7333373a7e3548459acbfde5f8f701c18da5ad34de7f16d4526340141bac3287
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:ea1a606002afe00fa7a8a3485225018683d52883ae6c34474be66877eebdca41
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:cc24257ad2fe6a9d3be34f4c1e50808c2c47f41af17d81e5ba1725587f28f99c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:96f43a6f8b6375ade3bf3efba8c87f24ae71032fa310d6027ddb36f6d9da5d94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:b7450ca27c345fdd5de52fa5b9c1cc30a36c47631f4b07f7a784ea09afcb3b81
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:007306dc64db6ebc04b9f695ff914e67de517712c71d285025f55bbf812f9698
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:a301d7c8441c029874fa306c3829b673050dc4dfcb53160abd4c9d0d63102f4f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:593a204711bec49e1ba8c4b171378c3a2f87d0ab23771f21b475dc2bfbe76d2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:f456e9565733017244f28c1f675cd27248b49eb3301ae87c581423df69f13278
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:0678b5df33714215407a3ce5940a358f89ebf02f670e88cfe73f2ac5700861d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:9325190b024eb0e6aed21394b7022a851310c715a89923f3c71acb0eb6b647f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:f7a21773d89f8bf99254f1fe4ae0c314d76846bdc4709b4353d45e65696f4947
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:6ed8aa38f172726b6457c973082d32a4f786e76f98cef92659471cf18bf6cfb9