dhi.io/busybox
1-alpine3.23-fips-dev, 1.37-alpine3.23-fips-dev, 1.37.0-alpine3.23-fips-dev
sha256:f692dacbf24c69aa5e7936ff96787ecd0a4566e2de661a28d005c845fe0313f6
Manifest digest:sha256:6b63a69b2173ee8850df1a1315e54707ff14c594d3a6877d1283c573f9d5d535
Size
4.22 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/busybox:1-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/busybox:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/busybox@sha256:abed329cd0cc4a00568f42fdad8284805616fd673d9a08725c746ae481e38758 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/busybox@sha256:64bcafae0e7d0cedefdb00d2256ea4175ec911cc4a92adf701bec57c8bbea1b8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/busybox@sha256:e699b42061625bf55faee3f5a7c6e820e8fa78d74661d74496e2d4f2fc315a39 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/busybox@sha256:64eb3dff1f937d6a1947bd81b1240e678e1d2171a3a01cf6731273ef1674df9a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/busybox@sha256:0db7e98bfbc4877af67c9c0a8c5c7dad7515fae3933007aea2c4547d1ab36551 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/busybox@sha256:fa829a59f452c66cd98fdbe58a08c3142f1c390b61be95127a40fbb59b890571 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/busybox@sha256:f6d1cd1c668703c3a87611d12c1af9c12d1243b06220f7af3a7dee70ab2ced20 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/busybox@sha256:f6c701e35f2f697b4fab41089478085a1b13937d02a05fcbdd094013906e246e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/busybox@sha256:4542ba3e7f316fbf3d87fd490d7fc92208d0a31d9617aa4f84cebc40bb81e6b6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/busybox@sha256:ec80c87c1226e5ae6a87bafbd3835e017d1a071faddc02329132ba9f7d539fb0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/busybox@sha256:f8608e6594a48872233bdbc566ad5e1f1ad89ed6f1c0022dc53c45723b130233 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/busybox@sha256:098347ddf6fb87243d98324f8a4b8de80b042cded4a2aa70b9dcadffdb4e4267 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/busybox@sha256:0f81b36e3c639673c5cb96282eae678300c531d0bf23996b86a54c25f7865b80 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/busybox@sha256:046592437bf60fe67d012e87814a4cd6310fdb5a6a5296e5a0f09c72bc8f63e0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/busybox@sha256:1ca8ed9b557a38ad67e02b65519f2e0d088fcdf148fe4e413ac7b64107632919 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/busybox@sha256:638c11507ce268a3438ecddc2074f16aaff7e8490c8043ef4d859ea3f52901b6 |