Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.2, 5.2-debian, 5.2-debian13, 5.2.37, 5.2.37-debian, 5.2.37-debian13

Index digest:

sha256:82425f234306fbaa348bb2aba48daab8d8c96e0d6d24bb6853aff1299ad5b78e

Manifest digest:

sha256:2ba43c405c3a05139a9ece48a8240579218c3932f58cf2e2c4e172a1e5b2336d

Size

19.71 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:7fd0adb1b97acb4eaf8d0d3cc139ccae22bf08ccd817dc622a38e1fdf34dcd13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:07f43ca15ae272bc40233b8a4332722a99ce8636989ebea89cf2c3e03c113469
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:f036f74869fff96078a07142c120900d29d129d46bed94860f1bc2cf2d21e1cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:af617576e05d8c246f76fa5e2a320fd82e8ac28d4da2819419faa8d1c6b8a9b3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:248a89261582b9d36c00b45a83d99de968386e860f40b8ccd3a67696a47836be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:d96600aa36928b14e09ad3736b5a4ba19cb753ee930e4c9743d8ae37e7b357c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:1e00bb5cc4ec2d46f3459cd4dbe3ef2c8fc6579d6f58f849abd91aec995173f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:e2b89eb5414aa7940162571e056de0f52e5cee0846938f61fc0b531a0891ea8b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:a64cf896b745472ee5aa6df07dd23ba17f733f18bf87cc10d7ea38dc9d2eb54d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:ebb2a707776e205b8ec40eb60002c97e12f46d5999a614ff34534417f190b0a3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:7b21f366045a6d3d57a1fd4b1e58fb50c7d87c6c42581d74903d98af25bd7594
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:7995eae2781e35428c318d035e411f930b945c135afcee3d14f09b19104ac958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:b577b675bebda9cc588ea13654f465a506f0c63712721d760c8704f37143b00f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:8d9ea54bae5ead89d88b5aed4d834ab973293c643b79abd81382d901edb3b3b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:bc13b7ccc18b2de66c56c8d62fb862daa0c618fb479ce79148ed917e310b5f4f