Sign inSign up
Bun

dhi.io/bun

Bun 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.4-alpine3.23-dev, 1.4.2-alpine3.23-dev

Index digest:

sha256:bbb258f21b4a1bc7fcc235a93b26d4097d240928ba245f0cafa7e67803dbc731

Manifest digest:

sha256:1cd62c782e48c29915705e5d16e3212e8f5d15faacc31788a7675f1c105e1400

Size

33.69 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:15a4481b9bd429a71f12f1fb2a1716eb4abd56f774def40ee7e9298148596de1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:a5f39fbdf22ff5fbb43d22bf66848f0910dbc6b493f48217abe1faddd7d2360a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:65cd0ffa44c1b28ee7bde0a4f62c11c4e89b52591648a53b67a7ff23414b641c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:13379c6fc274e1846d92fdf777958ecaf9ccfb15d1aee99bba5aa39f63e8be1e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:d3211b2b46c9ce6a3e04a2fed55f4488aa7419bcc178c405fd87dec01f058d5a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:153dcc807971e8f15cb3ed2a46d2eed1e7ecb81cc25697759a65830e9e3cddc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:cf589638467d004ed47e1d67b51199743180e63bee55748d0ebd629a842a45d4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:2862b789d777567c43e895382fc6e12bd78c29bdbd6928176df0d0ac9f89c63b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:c63de8fab1d041e0fa060e408a7eb2591d86d5cbfbfcc75501ad037647f19f74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:c3daeadafe8059e5b7b60bc2a8db273829363a6b41fdc06f39880a4e8b85b626
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:cb5fe470124fd934f229fe5e4db1aab605563f33a43f90a32e5a6e58b992770b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:621e4bae0fd72495de9decf8dc1231bab3ebf22e10ae3cf6e050fa7e77acae1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:87a44df3f169d6abad728b787d05cffd7e1eb64f2216f1e202de7f2fee292dbe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:53ee3b7736934859b17aa026a2abd69e4176d4f3b2b145785ca341d47a02b98e