Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.3-alpine3.23-fips-dev, 5.3.3-alpine3.23-fips-dev

Index digest:

sha256:a58b1ec3cc42d8170ff7f4e3b4efc0707d870059c7e174b988398ef0b8388fe8

Manifest digest:

sha256:1436ce55b3d96055c17dc308baaad0be7c5e320f16e36c8451aba76e335746db

Size

9.42 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:403b80dfd63ee3b44ed67738e81df086b29848df9587619c2713762b521d6fe1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:7bd1fd73c68a01400217fc4fb9617637452f4f45a1b0eecd159f09a90a0264c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:35040628661fc2ad44d437f07b312274251be0f42f574346cfd7890d54730f01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:96ab92a4662f36417064e5fa38301d741ead563ed99823fb6d3dab91f1f4a62f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:f5d9331586a6dc6ba16d82bdd7c2afad16bf42a9ec336f2d344489463355ce5c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:380550955c66f69eef1df71afe534007be98fefcdad9bbe5e9ad6f17679d176d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:5b1aba08757b93ccd3ab40bcb6c2372029f378f8af42f4b52018b67c33509067
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:91080090bc8bac78d1bef3b778371ca0ac7ca44510e8ecdad2a8f419426cf3cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:721c989c86db8d6fd70c2e78d93d0db48be73ace2a6dac28f4d194cf201b489b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:9510a65927d03dbe384fd787e1cd1ab28cb807349c6736cafd72a1cf4233801d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:68bde6c2f5eeaf67e82c445bd99fe463b340e3ad12b5b1e434c3fa8d234e8e5f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:84ace6caa8a76fee3a8e6edc5331cbf130df968fe4ea044b7ac70721a03bebf4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:2cf5999dc3b41329b8892aa10deb39ccb6373891f98b075d5bfd5dece30d761f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:7803ed507b01ce9479b3e8abe1abbb5f5d51e141b1db11004885c85c86f4a377
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:c8342a6f9dbe569dd7f60d42118ac546cda57ae5e90598a1779912ff2abb4a9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:610a3a0e9b6d7ab10d7600be544fc20a113617f491870380ed5786aa44f8c160
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:2a5620f230126c4bb89202926c4c94cdefb90e9587d0956e10523507a63878d4