dhi.io/bun
1-alpine3.23-dev, 1.4-alpine3.23-dev, 1.4.2-alpine3.23-dev
sha256:bbb258f21b4a1bc7fcc235a93b26d4097d240928ba245f0cafa7e67803dbc731
Manifest digest:sha256:1cd62c782e48c29915705e5d16e3212e8f5d15faacc31788a7675f1c105e1400
Size
33.69 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/bun:1-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/bun:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/bun@sha256:15a4481b9bd429a71f12f1fb2a1716eb4abd56f774def40ee7e9298148596de1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/bun@sha256:a5f39fbdf22ff5fbb43d22bf66848f0910dbc6b493f48217abe1faddd7d2360a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/bun@sha256:65cd0ffa44c1b28ee7bde0a4f62c11c4e89b52591648a53b67a7ff23414b641c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/bun@sha256:13379c6fc274e1846d92fdf777958ecaf9ccfb15d1aee99bba5aa39f63e8be1e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/bun@sha256:d3211b2b46c9ce6a3e04a2fed55f4488aa7419bcc178c405fd87dec01f058d5a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/bun@sha256:153dcc807971e8f15cb3ed2a46d2eed1e7ecb81cc25697759a65830e9e3cddc0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/bun@sha256:cf589638467d004ed47e1d67b51199743180e63bee55748d0ebd629a842a45d4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/bun@sha256:2862b789d777567c43e895382fc6e12bd78c29bdbd6928176df0d0ac9f89c63b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/bun@sha256:c63de8fab1d041e0fa060e408a7eb2591d86d5cbfbfcc75501ad037647f19f74 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/bun@sha256:c3daeadafe8059e5b7b60bc2a8db273829363a6b41fdc06f39880a4e8b85b626 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/bun@sha256:cb5fe470124fd934f229fe5e4db1aab605563f33a43f90a32e5a6e58b992770b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/bun@sha256:621e4bae0fd72495de9decf8dc1231bab3ebf22e10ae3cf6e050fa7e77acae1b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/bun@sha256:87a44df3f169d6abad728b787d05cffd7e1eb64f2216f1e202de7f2fee292dbe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/bun@sha256:53ee3b7736934859b17aa026a2abd69e4176d4f3b2b145785ca341d47a02b98e |