Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips, 5-debian13-fips, 5-fips, 5.2-debian-fips, 5.2-debian13-fips, 5.2-fips, 5.2.37-debian-fips, 5.2.37-debian13-fips, 5.2.37-fips

Index digest:

sha256:c3530dc48aace1ac40f756136b4c8059aec3d1f1797babde2310e145da50d291

Manifest digest:

sha256:ede7c27909fef7ac16db10e6c4c60383d2f43f0e7fa20a677fb41833a8fcc26f

Size

20.48 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:a7c420d9a6c607ec0cf4feb3640ae29bb86bfc9a41a779502d3a1a11c6d7c9ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:6c9369e0a8a24aee9afcc21021aebdc920b09fca92f99d524812afcb0095b962
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:1eb398cf5dd9467e4f48d684e702635a96baed70bc1cafe88502c852d9549c2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:50b45b2f24c3539e097472e71270aeef050c483d6c0afb2e34d6585f8bf79577
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:3d9f984881d0ba476e9b3e07e77563457de854063555be2fd6922050d57923e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:f9ed73226edc11e154238bedce2f62574c7800afe12ce6843ea21393eaf05d72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:a5287245ef64a96cb305f7ae8be2e51c01fccff4bb0081cbdd4c501222d762fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:f9354bf5fd3c37a5d96256883de5730ff92e88f73d688fd374df2cfd5b7e760b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:1865edb7bdfe8cc10741fa51525223ba5430aa1371d71d3ee8a562032c67e1a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:23984d102b2616e7100c713e89e210d56fb0afe12d8adc522831588b23b868f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:4344f4843a87201d1de30269cff178c99c5189bac6784dd8dc4a3eb20fc9db56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:d797b63d2f0a7b37f8529f26c47e35af79321774fce5705f9b6cc3817137164f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:62d185bf0ba2566d522f241c104d99bbdc4fec12cfb80d30220b5391d5b1c5ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:b37b516316d4b9bab23a1ae7543d5360b9950a0ab0bc012ed7da3c41957eeaf7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:6d99a01b940295087758e8345338cb8935ba7081f1b2db73fdf23d315204eea3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:8f7e46e439934500943cf8012e0e0f154d9ba111d5c68ede7eeab1e824f92399
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:811a145e08ff82ea678c17bff05fc2d80a0d3e049cdeaa61ceda946f6d80aa3e