Sign inSign up
Bash

dhi.io/bash

Bash 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.2, 5.2-debian, 5.2-debian13, 5.2.37, 5.2.37-debian, 5.2.37-debian13

Index digest:

sha256:3d6ff50706cfe3ec56722ec5de67be7280619b43eff997749b8bfd44eab658ae

Manifest digest:

sha256:a00e09cbc27c13aa12dd0151ac705a598da75f20cd8f2a3a1c8ba47b9c8383f2

Size

19.71 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:23c2c0f4e770baac81304a5444f0fb14ca8889286c113b01967e05e6b978ab5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:1bb0b1acd713dc2273e64efbb3d39dc0a2eff2d41f95a51b3e320554d204b3c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:056a8a5d4c91958ffcbb93a4f3802c479214e04a98a7a17e8315ed1dc9898d7e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:665101fd57cdc72dbe57c9dbcc402cd7149b7563c98ff2e564577499985f3d42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:e768413a114c512a1e0882b11805a50d7da3452733c6537b3e50381dda1a0c3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:afc9b2bbaf2cb957fb02d037ef55b79db17867146976300c8ab6e80f8b45c23d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:d3f4c366146f63b1ac240573508ee72bf41afaed0bb639e056f34529d816ae0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:7b400b6ceedd537e0bd135889e32a22fbb4dc58616d661ff7e71e53d3be9b65f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:005817ff083f061aa78247f904ce1acde7b8ee66cea185a146e4e7412b8c2d56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:6a3c0fca097d6569f9270b9b939e500cfccf917b4b7ba52fa4567d96222bb7aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:ed75203f7d94af52a666861be0a758eb2542bbd835ce15f9c1374cc81f7148df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:5a55ca0384efaddc0999c15e7cc03944005ca29cf32c4df47c830e4edbe234c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:3f06a5d933fa47e8f3bf322ae8d3fe1a1e9e41623052203ad791ae78c49a0e13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:f518e292f6d4a2dfc23da6a84fb9ed70f7268d08c339de21ba5d47b60a392af3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:6b66abfad2f1576109dc65591c259eb74c431feaa7dbf9d52bac83c315d3fe37