Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.2-debian-fips-dev, 5.2-debian13-fips-dev, 5.2-fips-dev, 5.2.37-debian-fips-dev, 5.2.37-debian13-fips-dev, 5.2.37-fips-dev

Index digest:

sha256:5319aec7788b0931c3aca8ac0982538c6197dd4f7a5c717d4e720a42bf892830

Manifest digest:

sha256:0cf9848c8bd07f40492e60f61e3fd5484a46604d8bd2b69900b2e4757ab16953

Size

31.01 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:29b06e3664ed6fd87b74196c9e6a76e0f9022fd813cf0db38b0d20767c2ac74d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:a2730d0191e4a8185efbb86d39e61ca64516f0f27289a70fadbf80d8c531ed60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:6b305559d086a66fc2dec3474a0c97e3ee873a3af918416c5d22cb1dc4b2a410
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:abc842dd1dea1c3cea1cc98cde70dacbceb9fab437d9807a2d39dd9bd3eb7e02
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:c78141f7e2ce9ecfc9dcfd3a499a52f0c62f6216371b44e5f6f4b38ca0ec019f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:46afddcd2b6b996884795bcd9be40eeccc0ce1370f22851cc2c6aa9b84e21206
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:0918a7a9ca9775d8b55d4e430f239266f036bf6ff446fceaf44e9b4445ec717f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:ced72a2b85f34e236fce463a9c097991839d2ef52dacb5b5a0b34b7d260ad0a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:645bebef841aaedbcb45152c84c1ab433226935bbd69426b7538269362c49cfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:5ea8cb26681bca371c1f43fc41411f30458e6ea3229cb4b7cf83ee8b8d546820
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:d459a97af2fbb452189f1633205d34a1bb1cff9c17d3f431c760c089ffad9101
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:b8aca40a352f704d30386b097241d98a22cad05828230b05630fed621b27c04c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:a07b6524e26431d207ecc6a22030d667dd2f726eff8d69361b923040e4a5dffb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:aecde69c9120a2f6fde7d060aa2c871e5b0a101397b37d1979f91f25fb09609f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:36032ac347463c4788103977b92d54b5857114f160e5096068cff7784f12515a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:1d098aaf3701861cc161a49babef88707860a42ab5e95dcd50dd7a6f51cd9b4c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:e924e787f0e222a2540bf7e1e7e2f8f5324c6cf078c33140584dd05d6a02af55