Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.37-debian-fips-dev, 1.37-debian13-fips-dev, 1.37-fips-dev, 1.37.0-debian-fips-dev, 1.37.0-debian13-fips-dev, 1.37.0-fips-dev

Index digest:

sha256:cd23f94a90b78eb2dd162004c315e7dbfd0709743df3cbf1c695187d5e6266bb

Manifest digest:

sha256:451770bc4af06a52cd9dabeb83ee37a4269dd879e84102e120477949178da564

Size

21.47 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:0686af513fc40ae0b0a41b7f930bc8ff1c093531a49ca91993b2a9408b52aff1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:4fd528773adf8f19b834b70bfe1db1036cf129129031c63f948bf90be8689b1f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/busybox@sha256:553bf1c12003ae6ee4905161c0fbbe2f263b84d4dc320dbe54418cf5a49503ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:e2c2ca1e02e8d4e1d4a8670a44778a93abca030882e64eb8dbb869095e423c30
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/busybox@sha256:2e309ad6439925582581b990f6296ab4355928f35a4f03ae551187b3747700ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:52a509a6484a844a3ad2139ce33116335516905a948fc0a85b2caacbe5d6886c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/busybox@sha256:fdae57c0f142baae28bee7d9b6a87d02a3676e4e3d4811d1200182a62bca77bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:1c788f71966ddfce1f091acdc8fe9182d156f0a5151a0ff71f1c586ef8557393
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:c1ed8e6122eac3aead8569d4704ed855191feba7f1d1c9c635bab6759be4b29d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:45148100c897a34d5ba78dc5837703203a68d0d1bd118b555637aa950d1ded36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:0ef75cc7821c72b63270351bf6ce778a0d5dc12a037d931474250b12b53b864a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:5988f02d30f19eeb3c912a77808ea0f0941fbec5de14714400b208a655c23af2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:cc7732d9bf09215dae7b8380d0e8ff93e69f50df6e93d4f29009f31e9492f809
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:2e0770501cea1cc780612428aa0bee5f4dfa6c02b375b37b1a5ebbcb0cd37e29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:bc6562c49e678d9c978468aac5ca8b255b618b1cfcb636aca2c2eccaeaa43b53
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:e00cc2b88cce96d016008de0e586b49b1d6eeace9ee957285931d235bb1c09b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:ddef468d019e03fd920e852f30ecfc99e69fac323a0285301eb11efa074feb98