Sign inSign up
Bun

dhi.io/bun

Bun 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.4-alpine, 1.4-alpine3.24, 1.4.2-alpine, 1.4.2-alpine3.24

Index digest:

sha256:9fa7beefc31ebe5dfc1bfc040bed4ac03f8bb7f1456936ef2d73533596fa27ae

Manifest digest:

sha256:7432ddea14c9e93ac7ecb3fdb78f8099e5d2c17b95c7673137c947c5adee18c3

Size

30.81 MB

Last pushed

13 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:0180bc33e5df94d4b4d602facecaae5862d812b399659fd2024b434bccdd08c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:aac3f05b7f0816660f1b3ac504e196c146099af8fff17c9c733936cb9f65d5d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:6067a603253d22156c497114781dcdbca887a4d263faa0dd9aaf0f65acdb6d27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:5bd79c423f1f51e93a1556ad6baeee9ad4d346da99ddcf0a31f30fc5d9bcd5f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:fd43e562cf781f2de84553dd97328e5d3741f81ef81a56f61577dd789740deb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:4511a636e94321e630d4c6cc2cf1f6d0a566f28e460ac9f896f04fb411940a1c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:fec58928e9e7700cb4860646c0157019b80e8457868c18b85b6e50005a85a95e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:37a8e453501dac0bacd9cd2128ccb5a32bf0224030db7d04dbc81acf5fc6080a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:5ccbf6762f1bf223421d261435b45ae1e9edf52fb8887fb33c3bfc2915fd70e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:ff311db6d015344ae4b2f5e4463d9254e869c446835b17b703e22f00b4b8e60c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:bc8f6fe58e8421d42d2b7c3d9f0f0cf8517bd45e8b71825e63d8073f6c78131d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:f71981e9623d55e56db58d2b9c15428a89f3e4e2697f34cd385206826bc09c19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:7e596aa9241583c3c2fcdd1ac3e4154ceb5f0797aa7234bab470349ea09795e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:0bc56d15bba3bd59f6c587cad6e9b4b06bf21024f47c7bbc7af95eb63cab50b5