Sign inSign up
Bash

dhi.io/bash

Bash 5.x (compat)

CIS
linux/amd64
debian 13
Tags:

5-compat, 5-debian-compat, 5-debian13-compat, 5.2-compat, 5.2-debian-compat, 5.2-debian13-compat, 5.2.37-compat, 5.2.37-debian-compat, 5.2.37-debian13-compat

Index digest:

sha256:095a77221ee906e5ebbeb4a9d6d359cd0a0c58ea60affb649b22edb7391052c8

Manifest digest:

sha256:6b8ea5c37c445366b9c57c52496dfe76932e33a51f10d36713967b6608a513d9

Size

20.80 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:a35a0baa604386d3bce296096e366309017c029fa9823c95945b8ad7f4515f20
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:aee90165f0cc28b3b112482739f93e6458d14bbf605a06c9d56baa2c8dff1296
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:79c405329f228674321eba21727fc7cfcbb2a3e4ebed09814e1846c46d5ee2e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:4fe8ebcdb2e654e894e88dd955fb853c3661c2e0679e497730926e1bf949a3ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:a44c61a3b85defce67134302606d10f7f0ab68e0acc78207ca52e277bfdf564f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:6dbffeb44c8964a9fb9f803ddad7461bebc8cf009c24d041743c0e815c18d58a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:fcb529528cc63855144200565a971f44f18c8fdde3204e0bf2ec1a05377d3b7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:c25edd8d8bb31198aa84a1040f1ab92d8522a8d8cdb65374a48146a7a83cb7c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:de6209ed3f1d2acfc2f9c3e51cb5990785957def82b2725a51c35bbe0bbc4f57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:9bcc702bcfb085715ef415d56d655cafcf90a6b9f294af9f6ed104f7dd085ece
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:8258e33c93f2614ca9198fbbc79497c691aa69a834c1a7a01d67d899da15bd1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:c4ed139aa305e96850a8b5a5c68dfc97a1da1b8cead37bb27f8a2f6ce86f426c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:4772179b100478c1c5b43072082e318cdcf095f6c35e9a0da11805980a2e6f30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:c68271bffd6c794b15ecabd8fa5fdc8339939a22e2dc26c8a5f8a5d9fa63d280
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:79b8820614db76cc79a97825183ea31d91fc4eb78a7166ae802416ec7658c3bf