Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
alpine 3.24
Tags:

5-alpine, 5-alpine3.24, 5.3-alpine, 5.3-alpine3.24, 5.3.9-alpine, 5.3.9-alpine3.24

Index digest:

sha256:25db3ea40a6c52587818994637c43ec1e622d0df7081d63bca1411ad6d4d8df6

Manifest digest:

sha256:c047d9abf6f2c8e036a42dd6e97950b9ccbd0e3702440f97c82171c0a048f1a5

Size

8.16 MB

Last pushed

6 days ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:ac830858cc67f631347506208e995063f0e832040076b3ed4122ff652005051d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:c071b19097dd0aadf2dec63df26035d87481a0bb52cb9c4d1817e9e6a4375df1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:cbcdc88724bc6fb6199a6a8636319a369e19e6e9c5a5c747ca1e55ccedbf0297
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:78204530101deecbe2ea8c5c6d24f21a02fa37b859f29b5673ded61947c05c4b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:563aaa6ce77b4ebb21876c950bbda4b0051a2702570f1b959dd3be6cdec80f04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:c9a8bf4ab4ce55b1580920ca932169a74d11ef925fbf530011586a09b0de2268
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:2e58bffd8356b7f7c4422f3d0c7327105d30307cad5c5d3b379ed4bf27dcca56
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:b1f3439ed1b12f6f3242a5a1a31af808faf50a0ed3d749183578a982c5487c66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:bc391839f8bbd289cbae5bd143de61c92c908633f0d8b7a0937f637c9fbbb9c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:ceee557fb007ac0c836cc5f3640df738c454957d11fd712d4b70f76eb81ce631
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:111a4c488d9157626fef17f8e5f0dd3f3f47c17dc840d50e92209bf98fcde94d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:533120749faa320fafa666eb484f6da327265dab58b1fa3dbd1b2f7c1cfa2e6b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:69f031a98a12c09994572f917987d7788c5e25fc906356d66f4378795f87ffea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:cf76bcac0714f70548d2017dc70cf52a257207dbadbaec3e2dbfc7ab9b45440a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:2f52e1c7cf72090508c67b8e769d84fd6114db10f0e154dd0099fd13908bf358