Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.2-debian-fips-dev, 5.2-debian13-fips-dev, 5.2-fips-dev, 5.2.37-debian-fips-dev, 5.2.37-debian13-fips-dev, 5.2.37-fips-dev

Index digest:

sha256:2bced59a4fd4fd3ab6eb544f6810846663131681ab3f9155e72136ad05add983

Manifest digest:

sha256:27666ec119daaabd5398b1fea14ad13109750c0727a5bfe0981fbcdab459d36a

Size

31.01 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:f6fe87ccd5e7d8080294da7784e25030e96d9e89dee1e869563fe085956f9d2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:f94f89f2530b9f4b3ddc302c164e953d556596b0e5d35242b96e646c586069e3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:acdf11ad0ce6ceacc300b236b48e079a3b9169e26d97c245064f36169b3eb505
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:ead0a1f64d85edfab82d0ffd493dcca840bcc3216bbd0cc5d26b9437df2bd76c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:c0b6835662cc73d0e232821e4e454b903db8c04a1c0c33e0f7d0caf45485d3af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:0e8e52f7c01b7ffea4b9af224c7761962122383b4e5d00bcceacd4c83beb6d8a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:0a2e1c6db622463f209f3312d497c5b515be3c263e89d2e241dde011522eb78b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:2739678ab1cec6a579544eab916c7e02d0779b2a89bdb5493f4ebcde0d078e73
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:e0cbeb61f798a14522c67b19bc497ce98f874ab2f5ea8d8b4a6ec962aa2b01be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:8738980b430cbe569e742a28691a1c81ad5d32390fcbf5cd149d7ded1c312239
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:eb188c5909ddf8f56977cf74368350a1726bd3dbe28b82028f6b3f7942c1562a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:74f053e1918920357e6dba459b447693a1fd165e1ef7e70586841bdd3abd8850
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:f371f55f48634a34adc5f9ca70629dcfbe9660504c0d0ec4a857adc401eff2e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:dbbcf80ffd9fadf6f0ae8878990dba4e26d0ce74549014c9bdc2c2e2b6805b94
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:458a948e78b53eb492f4c068533fdbb8779b24ec928409c20e8d686aa0f9a37d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:be9abfe3ffad34b2174d73d969a9d01b5fd6bb6726ab8704b947207cfec76ba7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:37752de87b7e7cedfad068847befb74756f265836a193fb3d7ba0d432e2758cc