Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.2, 5.2-debian, 5.2-debian13, 5.2.37, 5.2.37-debian, 5.2.37-debian13

Index digest:

sha256:6551b902de6a6f1a9fd1327227ff763cb3e7b92a2a6c83c76e4d80508f7f0006

Manifest digest:

sha256:bef9fdd0fffd335c4fda3cfc2054b33c0b9ddf04283b20fd374c3f6d3e37d680

Size

19.72 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:bf9a7f809bc0d3a5835ee500f9450ae2f6e86d59e4fc3b22a1076857abcc3f2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:6410d987505269a25bd03c59928698123a924a0c9d4f4dbb9d4e5aec734796ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:549c126340ea0c8fd4bb7e724dda039953c10cbacc942b7b6e7c9aac86821148
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:8d46e9cb3d861b623cb25bd30ad546adc6ea0eae97590ae664f38d1fe49b5017
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:25dabeb1cdc4affcf75b4cac12b9b2a332e479b055105b06472662b53b049c50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:ca2ba89f292f18682e5740ac307912eb91cddcb05227c8ed696f98e66cae8ce6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:45da65b98c4648896da22c0acffa9d2de07ecea6b32d7ae5cd69d65726882afd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:3e4bdb7d65bbb34156249e9060bf4b3ef87505328c43085340397eec91fafd92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:83413c06507f4675334322c1269055e201af51a0de99177c7361c24eb547ebfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:35a0f67f5601e90eae2d2af0aa4847b47f53472555e5a208119a1cbf5a166ace
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:032e21d18d0f6e3f26036fc8bb86227df3dde29b07332985f59adff56685fac2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:4fc752045824a27260e2b3bd9ad22a62a04bf46321684e8ce3093aeb695846ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:1a8f1c3ce32f83581861651e893f68dc08fa03594853021e5811dceb1ed3a336
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:ed26e5eeac3eceab48982e595ab2899e126b01e7e525973146c12ed8ccf6fc38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:a31720264b88c207f83e9f84f2361489a1cef1cc0a1eacbed3248bd43cd42049