Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.3-alpine3.23-fips-dev, 5.3.3-alpine3.23-fips-dev

Index digest:

sha256:5dfad282954058c928d09efa92d5ced9b570354d811b8b5a31095e92a995143e

Manifest digest:

sha256:ad475edef874247336c2f7f04d0d4cef65c765990c74e11ea505cafd881acf27

Size

9.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:69fb3dc1a039fa9a84644deae0fafac4726f41c73cd35b965f03ade5a9e6c7a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:e625d48d2dda309055dae1c867e12eab9e2931dd5b3723af432a867fe15a6ca4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:77807d54653b046824d0866c97c867077d9c8862725e2822f6aa1f279533db65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:476cb973e6151977032bd984c21b5c734e29a1ab669ecb88fa9c44ebac0480e5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:828bf8ee41a4f7c3a92f456874c993cc28c0672edb1b287846b17e05a611da6c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:7fd5f413fce84bf67c6f90ebf86517f6de6ce0e3d0c6ed5b350a7467ec0e0f56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:42e7f00f216a2764dbd7e30429a0545a0c06769f6654609b1dbc3f5030435ec0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:ce9306291da0281787d7e1a1195bf445f13a26ac08e3bcfb983482f1d8231bd2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:9af2e8e6098c475b455473058464f0eca5ae63c5991826af40fd7dcb77e1b897
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:68eb5a3d4c661d1ff836c1a03234b95914d1e6675d183361d98d17b19648aeeb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:f90df9708039a8ae309739e9b75a7703856b088563d8b6d59aed3cbea19b7516
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:bf687551ce200626741a787ae50ecf2c4d2257e4b4fd622448c2ac8886ce79bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:aac272acb11e9ba78358ff37ce9314ae4722ee14e09907178b9c484f54367c08
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:184dbe61d38dae897f9b45b90d1994959bd4e4c5c44ed07a66800b69146f133f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:0437ded4dcca21c97691a75f002c6885ea175dc2688a788e14950134e08f71fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:2f5e4a1044504640f2bffd0daece03524e17d837d8f0a387284deead9c764cf7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:95179a5b9eaa83ac8acb0b10dd6c1051d9b955cb577e7ad823ef1d4301f446c5