Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.0-debian-fips, 1.37.0-debian13-fips, 1.37.0-fips

Index digest:

sha256:5bd4f07bef16ea105a745b19018ddc9fe455e8628c9257ec19e286ad2e2bdba3

Manifest digest:

sha256:75188a22342daee7e6dceae4c4214782c507e480f6e733915643f6e6e7f0e402

Size

9.22 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:249b224306ec3962aefd820aa31b3ee343edafc378e7c91c1099cba983537619
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:4a410a85eb6854187d460a3b0462b66a832af95d2e352a5e0a4d7efeea48f2fc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/busybox@sha256:8838d9d09acb56965b99f6a80bf38fe481469940217d0f5debf63d50f3660c4e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:c42df6ca5583912fdb60fdfba65f5b13821d17d90a95c865b2acd951ecd39cb0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/busybox@sha256:c008b2317aec3296525386be0b4e05a3177f0c4f78953a4881dde9070502e629
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:b9a7f222d8635a7cc06f223c5b5b4b4b7b525cd676bff6f89008f750bdd73457
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/busybox@sha256:ad544c28e7a2d5fc647248fcb9d800f64a512308949c6be41b4e6bad24d264b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:7b2add892f633bfaf8219e036725f65f39f3f6b6dc8e138ec94b5deab5e9f10b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:9d2163a14e7e043974faec453879f49b6333d04376628ed22cffbd9c208dc15d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:6686c31753194cc1dc874f617fc8ed4e99b12e9f5f1fa8d8024b4fa1cf0381b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:d3df3b4cbf761736c86ef7c37889742fbd240840ebed19dc5b9cd31f1a6a1174
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:990093b8f3dcc1e20e39f2f091cc0532887400b6f9fc1ab9edf7baf7a8b28022
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:1f7f178960bc067d5ad1a5615a70a38a554365c23b403da13b6ba432642f7467
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:5c2cd8eb3c59f9efca1e98c78be2ba992b0345ca8e611f5a344076ad67f2ffaa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:737fb3b96533562452484dcb5fdeedc0da2f82717a8c6b9f8b360adb951a5d5c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:88f9202b49d5502e522ffffbc9a65d6ca2bc90201691c4f3cd111596c0985de1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:79965ee4b5e24ab7aee1ff9cd693f7efb5ea8a18483b6b8a3a1d22bbcf2725aa