dhi.io/bash
5-alpine3.23-fips, 5.3-alpine3.23-fips, 5.3.3-alpine3.23-fips
sha256:dfbca4df183e3fd92ba1c9d40713c8dff1e723bd3217123b0d0a5b6e97ddfe3a
Manifest digest:sha256:820024ffc419076c4ef9d3ff1dd0c47c2c9c2a67eb7bb484e535b914bf82f0d3
Size
9.25 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bash:5-alpine3.23-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bash:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bash@sha256:5fbe2e60791771d4441ef1e83b4eada1f272c355a5e1feb37d9b6dadb9872376 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bash@sha256:ebb3c8807936369f9c21c9e2df5ee7fd8ee7b47a2a6ca84c67d38d724c4e7fb9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/bash@sha256:badc17d8560963cb6f8cb724093a75f601fc3cbb125cc7444e81621c64c3d460 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bash@sha256:6e7bc46b51a947b906b180a2bae160f728082734ec8e12a33625940c7f8f5416 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/bash@sha256:e0eaa07a725a703f71c7647280fdddebb611ccabe83842ebd31c9c106c9c4125 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bash@sha256:7aa1aa8f875c4e946ad48dc1091e994e58100031f9c461ec4dd2073be8696c51 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/bash@sha256:862eedb2d764e7be1f776e4af8d18417fe49004f57cd849b3f73385386f15bbe |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bash@sha256:ad6c297e21f377f6545e7548072ab40c516f44bc84990e8c86a23adc4c8a9e10 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bash@sha256:10efb03e893a1d872a36181a9734f0cfa31be54ba82f4e4335be4a1b28f2c292 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bash@sha256:666705bfeb23573ccffff516642864bce6dfd88aa1f69f8276b8a62583e87275 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bash@sha256:3cc2a6beefaa4c8157ef9e8ba6597ba24748be18ded13cdbccae1e1ed3877cf9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bash@sha256:231d6ba6a60168753b3f5c1095da85d20eae926e160b9f3721fbc4dc138a4c27 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bash@sha256:824ed3f7fc67a0cce80b2efceebc8010eaee3faeb8e536cc4c30a9d52d3f6fd3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bash@sha256:0401831c6f142abf3948fe9d30640e37ccb7afbdaef9a2ae1dfdbfa4fba934f0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bash@sha256:0cc572b91cf087673629e823c38dd18b02e8f513fb8438adf1155af68ede7612 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bash@sha256:3afff447c952f52132cb4ef8531558d077904778f379364e5cdd41e062b58aa7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bash@sha256:95a7617f98bbdc97a134344299b0b2b58061d083013d27f07a913d7bdf90b1dc |