Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.37, 1.37-debian, 1.37-debian13, 1.37.0, 1.37.0-debian, 1.37.0-debian13

Index digest:

sha256:b3620c618e4622e1037675820c89a34ef3091fbd2e31552daaae1408a6fa1ee7

Manifest digest:

sha256:0c4a45d61e07b9ae61a473f02802a64fe4123e733e56f3ac52eab2764b065043

Size

4.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:39c9c47fc4c241eefb4c9f14011b322ee6daa09ba6dd3fdb6f981260e242d1d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:06b9ffab042975efb0675bbbe8b91214798e735397ebf6e3ffe97061e25e30c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:2879cd23ba8d93243b4268e56c264f27183d3bb5ff3961617935d50ee7ae946f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:d65d2f71d7a6e5d793f600144b10543db54388d7a0edce47e14fd824a67a4876
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/busybox@sha256:d7d367866c5695b7f381582f575dfa8616b4ce99179dbb00f074fa4f02a67433
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:a9d584dde1031c56d7a81bc35d7a306ed5defe2a885fdcfcc36cdc996f50fd02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:90a1cd429e00f83256b90a0e602a2cb645c1f9e62bfc9d36ed2d75ec27eac539
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:7a4f5ab4c7da497f759c530f898427ed5cefceccfdd5a259fad3426a19b116c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:69a161b42339328da2112698d9606c222b3c2758bf91e10856628fe91f79514d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:553fae437c72087f1a6e2aea5bb60d4685c9b121703044fb47adcde1332a0a08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:5d60cee637a3cc5463d6bfb4702e722a89dbf03db9c1345e427bc9faa034a7cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:59cd9ca80631c32704ae256bb9577f84ea4623ac9d09e27b162b31e912489205
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:9cc1fee9fc38fea5ce840f51477e824fc892fb77bb12053c4a57a3903bedd851
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:2d4c08d62f55f3601d786e81057bc42e09b4f2c8fbe2d49f41e070b46d2f207b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:7932ba547382ee9763326d090fda444e5cb8a351c63a0d53763dac9a4dcac0d5