Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.0-debian-dev, 1.37.0-debian13-dev, 1.37.0-dev

Index digest:

sha256:cf4763e4bfffdac72dce22239cd9f4c96b3a35caa2094a70372fcdacd35f9e16

Manifest digest:

sha256:b20ccc52bb47b5b63907372b327c93151aad70d5b53520ea51f3ef4100c1a6c6

Size

19.38 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:c778f60c44dbab922ed52438ea7df006c440f02051799734a7576e0bc92a9060
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:d6cd83d2bf367d2750a5f0266de2732c11f868a810a4bd9ce7cf77f695043384
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:1bcbf80737a8ca45da7cb11cf0b785b7dbcf635dcef15adcb2e71fd20db27be5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:3911dbc75ad11f19c802db853e86a53c82f1c30b953ba8379c5ca4277ca642ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/busybox@sha256:78b3f3ab8dc0af791cfb4f018e2164a5c709f859900d2ebe3e93a4c1ad41eb6b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:c3df1927e86103d1eb84061fc114a833ef6bbe20cd5ceb07409f53f15bb0fc80
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:34040798823440a1d1794ac5c9b712da0e0103bed783e631536e52d2ecb4bbd6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:2c907cc35082d423576351bcd684a8f962d5f39a6dadd1ec63970b723d67da0c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:65cfee7ba2ce50caa4d909b09d9e24d10496c5e34b2095e84958e8a72a9fcac4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:ce8d7ff6d2878e26450f9a7385b75730f8095bf513388c8c3f49ab0600932c30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:e6a77ad88468df7b5667860b8c7dff8e7d86f6cfbd363a9c98cf0fab409589db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:9b5d53461545f2def4983c4371805f56f78c7b60a949acb51ec7e7c81de3b387
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:bc29c5a0e25321b8b6c65b5ca9421e202321171238ace6ab5a82cf82156d2630
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:fae7697c8d4c5be0bb1eebd994956d3cec6c8e12b4f5d99be69d2a60623c3c67
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:6e778dbdf15a05f8851b4057b93dca6c43c1934e1853884ab8fc9d01a45b6272