dhi.io/busybox
1-debian-fips, 1-debian13-fips, 1-fips, 1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.0-debian-fips, 1.37.0-debian13-fips, 1.37.0-fips
sha256:8207ffcd230b7452a38082d3497e0a062f62ed5c1586b6cc21a105b9feecf212
Manifest digest:sha256:ed12495daa3786216dac142677e3208dea57d564fce821cafd8eff6f28733637
Size
9.21 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/busybox:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/busybox:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/busybox@sha256:9bd7e2cf1a8c0716b6044ac88e26894d8db84c87c2ed29a892051d33a837c82a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/busybox@sha256:aabbc5a79839ba42405f7a97c9a316c7bf0b9b1f13ab4dbd7648e20ee40e6001 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/busybox@sha256:32164f5a8f8dc130163fb94892a2163d36ae33a1a569ae41c297539416da603b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/busybox@sha256:94b6acb5fd8a155a3c33d366cc8eeaab56aedd5d1cbba3f93bfc954b935b520d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/busybox@sha256:01f19810af01c900e72c57192b797947b6f19551053d12c55e501df41cb67b46 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/busybox@sha256:30749435b817eed795afb808e587e48a20b04cd5babf63745aebd3bd209ce82c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/busybox@sha256:07579d3421e7cee70cd4ecb5fd1cdef0378c2044a300719f3e6161b10d29e8e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/busybox@sha256:45e56c0e8faae30ad2ab7a170bc5a6012852896e1d618667eccd9ce69d4cfdaa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/busybox@sha256:e8149a0a3e623daf06478d77bf99342d13f8f335486171c387dd33846a27c691 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/busybox@sha256:5f3b09d222b795228355bfd95b85e60ad8a6ab7cd26f515b9996a47b90cc8dc3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/busybox@sha256:6a15ecbde7fa14f6f35f42ec0de230342cae545708b1bcecbe8317f856ea0340 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/busybox@sha256:e373ddc66f640fa0e85c154f9017033c20c358bb87d8f7c1bbd33fb8d42a1ecc |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/busybox@sha256:a352307b574894f5d9fdc3624ca82acac6ec069e12daa1af6d7afe253c45eee4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/busybox@sha256:5c136d5ce62ecdc0d59271d0c8b8a48637b10ee5c3ea11069361616dadf70f77 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/busybox@sha256:e2863f616623f9c9e520933d10e23a091c0ecda70e5f38786170c4d957be2c5e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/busybox@sha256:580a38a056a1f3782377bd3d26935922e3e81f7282485bb3b1c33d9a58bc990f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/busybox@sha256:db489432ff1c5bef125f931126f95751ea628ae07b62a55b94ff96af6539a38a |