Sign inSign up
Bun

dhi.io/bun

Bun 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.4-debian-dev, 1.4-debian13-dev, 1.4-dev, 1.4.2-debian-dev, 1.4.2-debian13-dev, 1.4.2-dev

Index digest:

sha256:c26f62756efe1d8902026ddd365f960008cbc1592e78648034bf26eca4587c29

Manifest digest:

sha256:21ac8f751c00452d992743930bbfbd14aa187374297c51b19066bec2af22d202

Size

54.26 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bun:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bun:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bun@sha256:7c866a50fb43c1ddd5af1d8ac7f24ee107d7eb17e64d8666b22eebea5e9e667d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bun@sha256:cf67d2a6c0ff47fb840ab2195ba1666c0e04bf136b0326534afedd852659e956
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bun@sha256:4f586a6de52b3c17e7453c8725b6e1c6f9e2f4ef7a0a72070f0051f86816e18e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bun@sha256:e3a42c823d1f5a00198cff2cd5417f7a2477b4a371dbbb86b0ec3adac60e20b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bun@sha256:a3704fd71fa92fe473272dad98a3fd043fdd75863d62456a251d3b92bc73a013
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bun@sha256:5d4c2f9e28befa26947ba60c5dafed3ca76fcb2a3aa7740f747340d86d0fb88d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bun@sha256:e01cfdf9f60734c5f3614ac5d928288b88de19d826939d135dd48f8f11094e0a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bun@sha256:454f733c1916e8c10212a6e280e4c29020347bd2e2eb9e507a31c23de467a56b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bun@sha256:db90d4aac55fda015d254c93e0bfaea037c87c98a92fe1b0b4dd260f27cb709e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bun@sha256:7068a603a60e5c371451b219977ee0027e6923fdd427c3df6572968ba984b2ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bun@sha256:c84e4505493e6ef55f1f4f5ea6e7421550cc1453c9bcf70d8f58bbee43c2b6a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bun@sha256:f1777ba0e7cbd2402b616dbc49f8fb2821ffe2e69f44f4e473c0c052f4c0ea91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bun@sha256:0471180cbc7514c1b9fef239c8225ac3226e3ca25fd9047023fc9d00524dfbb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bun@sha256:4e47d4361efa575d3ab515189859d0be282132f485191b14af9cdae593cbe998
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bun@sha256:472ce22b2bc97f4c91b6c2ea5982a70c1ca8ae6447b2e6005dc5b8f92c7ee67e