Sign inSign up
Bun

dhi.io/bun

Bun 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.4-alpine3.23, 1.4.3-alpine3.23

Index digest:

sha256:162c9bbb91e64f978dd84d7854413e573a1c9f9e758d6b5e5d1928608a80d69c

Manifest digest:

sha256:be8408ff70bf6be08def191abd53c95b2a93c89068e273fccfaff9a747f021ab

Size

34.57 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:2a3443fccedf4f7ddf07383ccc694e052aa3a6333443156c4f98cc34a9328d91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:e75bfc1097c33eed2800437d0fbef3fd49220b8e95ae72ed7289ca6ac07642d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:d2509a12b3aec71cd45cb330cb4e0c74946524761eb3501be5415d6509095fd8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:f3d68f6c6bd9e5d12288948f3de6ad03bc8e13538c7a2e4b61151ce29aeb8a91
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:dd5be0eca281718fa1191af12382ace0b85f35d8ea575b92fedcbc5c9e2a61d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:dfcdfd80a3df8b96eea74cf355cafe1662dec174080c287b460af425d3419e4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:b74fab45edd0f7d682fb79845a7d7db6d42482863444ecfd3f4038a620903113
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:08f5ecb029b0e3a8386882ea3cb7234f5c2a3d0c793ffb69d040b38138ff8d37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:dc76fda5216276d12b399a46168c24907547211407b8bdd455a67e7a804060cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:cec2e101d20107b6fff3826df083a54f0693a59675b39b82efa72dfd385b60b4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:d9b63514096e3bc63e0acd75e7a5ed6c951e4b38f197082f384a78904cdb73d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:f66b638d081a1e0b33fbba476fba2e43a095072c2eed623b48b134e710302d73
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:a2cbfeebe91f947f0bdd5f828689cb0cc58cecdf7e078f723f75333bb04394b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:c7fafb2eda5564f09dd388bea157b8ba7db061c1ecbc542034adb3e2b707653e