Sign inSign up
Bash

dhi.io/bash

Bash 5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5-alpine-fips, 5-alpine3.24-fips, 5.3-alpine-fips, 5.3-alpine3.24-fips, 5.3.9-alpine-fips, 5.3.9-alpine3.24-fips

Index digest:

sha256:8217e9009182bbf99c4f87f4ebcfac7ef84fe324ffa5e19bd801c5b2ff53f054

Manifest digest:

sha256:f5c6001895b21f2ce25d40cf526802f226bb8cf79ea50424d5606e73909b8235

Size

9.31 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
2
0
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/bash:5-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/bash:5-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/bash@sha256:afc494d392b6d4d9f54621c2ac9411b45338c5c32b05cf7dd7b41cfc67a3d88d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/bash@sha256:15e2dfd937367eb1faa40b89f804bdb4e5ae52c17892ac100f8b8a21aaf55163
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/bash@sha256:7fb84c578c848d1e8d289a574826f739d46c1fb2c327d0980c088eae94733b27
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/bash@sha256:f1e5317d1d6812c2a5dd89c657bcc3ae194d020c7a7575d27bbfbeae8a7c9e64
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/bash@sha256:98072c253f79495f859be2c1bd16da6936fd5dac8403294180c67c7f2bb4739d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/bash@sha256:f81c57ea882b87c83d6f43d73e2d4e821747b08f59bf1e94404ed9cfe3bcfb95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/bash@sha256:8f1b96aefade0b67fd763369ca7bfad3d8470401e1bfa6a538c45ef4a54046bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/bash@sha256:a3db958ab501fa497957e8ece08c7437ae870d0c2e913266c607de6c7aa49ac3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/bash@sha256:00f2d391abe9aa49431f5455d64e51989d5e5a770b47189a2499afcfd0f2e8e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/bash@sha256:42f04e9c043caa15a1e9526e0dbec961589c8699d6b0f7ab5ae1fb01f1d21e78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/bash@sha256:9e0da056d5243a91d94c21e2dbf7a49fd5589c162a3993fc574e70edf8e8e3f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/bash@sha256:b2cfbbd57ee95f577e3d9ce7f14ef43f28b676741fc291910854a4c88a1c19e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/bash@sha256:af203390d31082a4b3dfe9331fe65b19871ae6307a2a52bb3ae30012ffeb9235
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/bash@sha256:d6c45c2a85eb4ae42f1748df50e7192c2c1c331809a2cc795486023afd08f640
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/bash@sha256:52a5b7975783940dae0a95b24bfd7bd40ebfb4acc92a118c5e62c96e81eec799
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/bash@sha256:67150eaa2673bc431d7ac145be4b2171478fca5b13d25cc5c4618481b69380a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/bash@sha256:fbee0fc1c6237cc80ac92ed67f855132e085b0260f3be22ec152313961fe73cd