Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.0-debian-dev, 1.37.0-debian13-dev, 1.37.0-dev

Index digest:

sha256:4631856b8221082606c23ecf50c2250f690b6a02df9a82c4cb944efaf7ed160c

Manifest digest:

sha256:234d2564211c1d534f16cb7f37c9e8499ed79e1167908a89a8ef9f884e7a7222

Size

19.38 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:85b1a51cde7b5f97744d565795b2ffe6e2dc123c959f1f3eae33be1b61f63999
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:072d309e427f7dd4284f8ba66265a4dd755acab51042b21f098b848d4b8473e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:041e50908e609954f91e07dc43c3462154e99ab8362f0f303e3a9417cf21924f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:493507025fb98c743d3c1d25b59cd3d0c6e4a81cb5139fae504716a31a27a3ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/busybox@sha256:cbbe335a5b1872a7d8cee0e1bcec83eca82347247f1ca0f1683d76bf58037045
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:45c8a330a01ca8f6ee1754ec7db4f8a14a6404578e7ae198084d7d9696f55cbf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:553878b017fcf0852c3e81ce6f23b50298ee3b08d3d64247c0ad925980057bf5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:8a15cffd53ba8d97f81ab88721fe731f8540bc38437fb4845df4167da200a3cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:7bf97c7a41016040b764faaccfe313235d6e5d5ada5ae31d5ada7dfed5b86aee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:f6f05d7df62ef2eb261cc6e8a76867c9d7f6ab4b219c21d756b3c4f8b151a0fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:ad6fca67568d3ca9b572222310f3700aa2530d1b4f34321d4b1815a3b1dae754
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:09bf58411e028208cd7f5589c882a6eeaf82fd6eab42c06ed051105638ef91fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:e40a865b0918c5003286cd6a1d2fbf8d6861895c6428e177546d00dc4c2df9dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:f936a6773ea934277a790f10433982bd98b3c864c10260eca4131fbafcbfdbae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:8ad2b19614a32aa741b06cad2dddad2994380797427b3288415cae7e60d831b1