dhi.io/bash
5-compat, 5-debian-compat, 5-debian13-compat, 5.2-compat, 5.2-debian-compat, 5.2-debian13-compat, 5.2.37-compat, 5.2.37-debian-compat, 5.2.37-debian13-compat
sha256:9d6eda9f7d4d5f36aa03ebd77bffe7c4c7f9e5162273fd78259454426fe04de4
Manifest digest:sha256:737669ffa956d42017b5e5ae0c8e71e296069173fabd18fcc62cd918e7e989fc
Size
20.80 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bash:5-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bash:5-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bash@sha256:f15076b994656692fdf386f588b2c9d5d46a972d6be43660a669cdb3db108466 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bash@sha256:3ae28dee042838576a559d0d43d13567cecc5f4743275056bd943d222ede47eb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bash@sha256:735549bf30a40fac01505678ce1ad1dd72f21eed998851c642951a5b4d5777fc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bash@sha256:f7979c5cee533a93b4e7597ba69ed71326d87bb08f53c1adcd44be59b7d63a4a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/bash@sha256:1ad718f7ccdcd4d40af05117f18308417fe3707f21394fdcc09856f970d8384f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bash@sha256:211a39a6616baf75c55e01f08fb2aaf6b717a94bedb1d050d4c7921f23cff7a0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bash@sha256:2b9e02fb76920722b954ab73d0d27d90b2f111333b75140b58ea5a4bfe3f9af5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bash@sha256:619304dc10da3f81e2d2da5a8dea0d022801761714e906e6213731310fe49367 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bash@sha256:84509b08cc5280f2eb58967781740784b2bee6d4288e86fb67f556827398336f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bash@sha256:335aebf84cb1f1556f56312d13f7e391c3c223412616756f7fa6d151df8c734c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bash@sha256:b70b4c0113270d7e9b7db2d9a0ef64f6fefc2afd9ef4afe0eafe73cb02fa5baf |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bash@sha256:ea83d51f096e9a76791393c248700c09d14f99ca57d350183eabc4583dde8117 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bash@sha256:d3494f36a445143c0ecf418defa3ae242fe5b645f719325fbd012857135026e0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bash@sha256:9db6a9a5ebbe324bb82e640fe6e9629833156dbab058871e32ab6e4504fadd56 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bash@sha256:066c719998e96f17ec08a6ea1aa9168e1ddac2a1f0dc27cb14e4b6c991839358 |