Sign inSign up
Bun

dhi.io/bun

Bun 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.4-debian-dev, 1.4-debian13-dev, 1.4-dev, 1.4.3-debian-dev, 1.4.3-debian13-dev, 1.4.3-dev

Index digest:

sha256:41696a729248c40c06aa92f62a704460b34e5b8f77706e9393e016b4d77cb438

Manifest digest:

sha256:0b92c8145c8c43613e48221ba1767f9e67b1114a04ca65a1eaf7a2fe16de481c

Size

58.56 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:65e900c3a12918a44ca2f9808460849ba6c8f593961d47e2676a89a634b9dcbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:42f46fa86b1ef9dea68ffb9099dc06f3ec7d28ec64542b89de3f623370b47192
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:bd656beb722154e9d2a2748ea7f1d5cf43f60aba37a50e3d1b8745af1285b2fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:45b8dce69f2db9f0fd0bf0724b8dbdd0d3031a398fcb49bf78801042a142755b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bun@sha256:982c1dfc713316ce44bfc422ddf2f6053f3315b54ada241549a98a265daf76ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:14ae4a377d6f0ca0292a9a5e89612bb73100f89f15eb178cc8508c91e56fea16
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:163aea3baf3006da5a0d6182dc64d2fe8015bb13f6b43811d4f37b8e05ebe146
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:a72c15fcefb5e4c0644ff6de5fdf541069720236e4c32974c6471943b9ada7d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:a43b916e098c1b06d37171a07bc696bc199ef907e62d76ba5c57ce3d45ff8748
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:5b66036900acf1e432539af603dfd52cf342ddf3d767e1efe5ac0e97326f7244
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:7483ef617ffe373a59d7c1bfccf9cbe7d66fdefa51c3f855227e7146bb0f4d1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:21464269e01cb0ca9fb8e4afb15a049a42f8f22053bde082b6d1894472c9cba2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:aacb33941e1af79564acaa06396812b4813fe4e09934cdbd5d2ae1b753380d7d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:c33e90c017a10efd147f52137380b15b0ae081e21ce05449e5fdaad0cd2dbbd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:5eb2a5aaa5f1bf88b56b20a98b825ae560ddb5a7cc4b11bef5031a57224207ee