Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.3-alpine3.23-fips, 5.3.3-alpine3.23-fips

Index digest:

sha256:dfbca4df183e3fd92ba1c9d40713c8dff1e723bd3217123b0d0a5b6e97ddfe3a

Manifest digest:

sha256:820024ffc419076c4ef9d3ff1dd0c47c2c9c2a67eb7bb484e535b914bf82f0d3

Size

9.25 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:5fbe2e60791771d4441ef1e83b4eada1f272c355a5e1feb37d9b6dadb9872376
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:ebb3c8807936369f9c21c9e2df5ee7fd8ee7b47a2a6ca84c67d38d724c4e7fb9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:badc17d8560963cb6f8cb724093a75f601fc3cbb125cc7444e81621c64c3d460
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:6e7bc46b51a947b906b180a2bae160f728082734ec8e12a33625940c7f8f5416
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:e0eaa07a725a703f71c7647280fdddebb611ccabe83842ebd31c9c106c9c4125
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:7aa1aa8f875c4e946ad48dc1091e994e58100031f9c461ec4dd2073be8696c51
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:862eedb2d764e7be1f776e4af8d18417fe49004f57cd849b3f73385386f15bbe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:ad6c297e21f377f6545e7548072ab40c516f44bc84990e8c86a23adc4c8a9e10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:10efb03e893a1d872a36181a9734f0cfa31be54ba82f4e4335be4a1b28f2c292
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:666705bfeb23573ccffff516642864bce6dfd88aa1f69f8276b8a62583e87275
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:3cc2a6beefaa4c8157ef9e8ba6597ba24748be18ded13cdbccae1e1ed3877cf9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:231d6ba6a60168753b3f5c1095da85d20eae926e160b9f3721fbc4dc138a4c27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:824ed3f7fc67a0cce80b2efceebc8010eaee3faeb8e536cc4c30a9d52d3f6fd3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:0401831c6f142abf3948fe9d30640e37ccb7afbdaef9a2ae1dfdbfa4fba934f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:0cc572b91cf087673629e823c38dd18b02e8f513fb8438adf1155af68ede7612
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:3afff447c952f52132cb4ef8531558d077904778f379364e5cdd41e062b58aa7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:95a7617f98bbdc97a134344299b0b2b58061d083013d27f07a913d7bdf90b1dc