Sign inSign up
Bun

dhi.io/bun

Bun 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.4-alpine3.23-dev, 1.4.2-alpine3.23-dev

Index digest:

sha256:f622fcf7d9677b071b288b4e57386bc18a45c27798c3a0c2bf2cb8f1a0e3be4a

Manifest digest:

sha256:10024ad75042c5504591d76507661357ae414d44e5d93145b6f164a28c6f9c11

Size

33.68 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:221c6beee7d665f7ad874791aba0e7f95ab05b479f0f343cd688b8e76e770579
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:e1a9afdbbe1d5142da49c7d4699c6408654eda5b06cb025bf80629c87fde444f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:b6347ad8144b900ce0cf4dd6281729b33eaac0bd378e33ac26400189c4f958af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:e593b5e81981ddcede1a54413105675ca7be36b7c29d29318b6f55db33010713
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:3790b5751dd1ea82dc10dddbb4620c7fbb6c1bb29793f9560e319c9482bff207
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:6d09433cefb09207d320af905e86f648b48546b74873d8b2f01aa4a9c27eeb26
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:0f5b04461d61d1131368accb87b9430c6786a3f39f5fb50443627153ed2b4726
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:560c8ce0c53cc79839e659dad885f14a991ac4eae83860b8abf0151a055626d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:71eea4826e3e7f79f63c85a2ddd85cda56b92b7b185d8129f49ffefcb0ef535b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:4ff147a821f52b351f1ffa0044bcce8a5ac46c165d3ef559fd7000458b2a6fa4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:651848b03bc854516056337198e94a6c728f73176df92d0cfa9616ca546b2d9e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:242775b919d6cb215f0c799422a7f89a442e1dc3c9aac6d67cc2ba96c6a10588
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:a20404594c8217309b2f0442865e9014a77c6376a6914d6a0f69b6245d25571c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:3e7613a6bb1a31aac7ddc5e6a1c8fb34290df9b28737453c31a6460ddd881b71