Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5-alpine-fips, 5-alpine3.24-fips, 5.3-alpine-fips, 5.3-alpine3.24-fips, 5.3.9-alpine-fips, 5.3.9-alpine3.24-fips

Index digest:

sha256:de133ef51b05da7e014883713428b2b8d6c5be5f205c4ff14a0fbe322e6ff76b

Manifest digest:

sha256:682471453bf892a7d008d377aa4725ca1db9102d4f478937db8f8da52be7dbcb

Size

9.31 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:4fcff4fc8bf931d81bbcc732b10df230f64ae36d48b58107dfcd9d2f6365c62c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:de5fa2f130c2630cc59c2f288df8fda349b068837ee4c1eacc2887349395ade1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:fc55c12182be31a2157b3f6af36b1edb7678297699df7f1fa163e6968708a339
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:319d839c93f3172e6975c1ae2a478f2653992c48e56670bbb7cf1a369de559c3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:a3bc3c96c92c38d074260b28618fc4443375b7b8eb0c84c55aa18fa16922e5a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:b954efeb918510df8c76392ae67c402f3068e27e16eb38eb1e4197b1570b245f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:9c44e4ff579c680c966a3cba425256046b5985f705b5ac2e4335985b714ccab6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:daccd54849f04dae6a2ff0f5c9119bfa7d5d36fa4f4bcbc633510e2fa428fa53
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:36d9f2d6e1c7d627e9cc21e3831a0f5455423829584dfe47fd954aed5c1181de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:ba28a9184e6df5b7d1d48e93db0bb4dd3f4f7c8d114183c4b24bc09f259f82de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:81ca58d8d640e2eebde2ffa20b2dedecf5e9f037721de0f0bfb84973f49055d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:3ab4adc182ef84c4000e11075d9243dbcf87e36092e9b1bafa953ac504c397c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:85855d4572a81767f664ce9b87b9b2bacdaef901b6dcdccf272cc25b40c6ee85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:e760f6f628be1af61cb01607a789dbee34b849197cf262e399c64e9ef20954ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:398750b0d8b7f758438617a56738108fe48de02dfb64d6ffb2a52e9c78ab148e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:1dc6646ae530b8c816fd8f15c81ada4463c3b3ca9c8714eaa2e64fdb2f98a9f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:ff8b25bfe373b3a4a5aabf2529d527dc82a681d274cd193fbe8309a624e22616