dhi.io/bun
1-alpine3.23, 1.4-alpine3.23, 1.4.3-alpine3.23
sha256:162c9bbb91e64f978dd84d7854413e573a1c9f9e758d6b5e5d1928608a80d69c
Manifest digest:sha256:be8408ff70bf6be08def191abd53c95b2a93c89068e273fccfaff9a747f021ab
Size
34.57 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bun:1-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bun:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bun@sha256:2a3443fccedf4f7ddf07383ccc694e052aa3a6333443156c4f98cc34a9328d91 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bun@sha256:e75bfc1097c33eed2800437d0fbef3fd49220b8e95ae72ed7289ca6ac07642d9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bun@sha256:d2509a12b3aec71cd45cb330cb4e0c74946524761eb3501be5415d6509095fd8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bun@sha256:f3d68f6c6bd9e5d12288948f3de6ad03bc8e13538c7a2e4b61151ce29aeb8a91 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bun@sha256:dd5be0eca281718fa1191af12382ace0b85f35d8ea575b92fedcbc5c9e2a61d9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bun@sha256:dfcdfd80a3df8b96eea74cf355cafe1662dec174080c287b460af425d3419e4c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bun@sha256:b74fab45edd0f7d682fb79845a7d7db6d42482863444ecfd3f4038a620903113 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bun@sha256:08f5ecb029b0e3a8386882ea3cb7234f5c2a3d0c793ffb69d040b38138ff8d37 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bun@sha256:dc76fda5216276d12b399a46168c24907547211407b8bdd455a67e7a804060cf |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bun@sha256:cec2e101d20107b6fff3826df083a54f0693a59675b39b82efa72dfd385b60b4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bun@sha256:d9b63514096e3bc63e0acd75e7a5ed6c951e4b38f197082f384a78904cdb73d2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bun@sha256:f66b638d081a1e0b33fbba476fba2e43a095072c2eed623b48b134e710302d73 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bun@sha256:a2cbfeebe91f947f0bdd5f828689cb0cc58cecdf7e078f723f75333bb04394b5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bun@sha256:c7fafb2eda5564f09dd388bea157b8ba7db061c1ecbc542034adb3e2b707653e |