dhi.io/busybox
1-debian-fips, 1-debian13-fips, 1-fips, 1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.0-debian-fips, 1.37.0-debian13-fips, 1.37.0-fips
sha256:8207ffcd230b7452a38082d3497e0a062f62ed5c1586b6cc21a105b9feecf212
Manifest digest:sha256:ed12495daa3786216dac142677e3208dea57d564fce821cafd8eff6f28733637
Size
9.21 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/busybox:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/busybox:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/busybox@sha256:9bd7e2cf1a8c0716b6044ac88e26894d8db84c87c2ed29a892051d33a837c82a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/busybox@sha256:25e459c7721c23758c71ba50d6c3e21fb812f2e5373356e4aeb04bc9a77ccee7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/busybox@sha256:32164f5a8f8dc130163fb94892a2163d36ae33a1a569ae41c297539416da603b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/busybox@sha256:f0c083f8e49dccfbe233bbf482ddeb20197cf778b7006428efae2820c4b5c25f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/busybox@sha256:a5ef52e0ce8f209dbac55040fdc472560d255b296eda58c8a22dde485c32e258 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/busybox@sha256:9df745aab3ce537f0a036a728730a6452403415d6e3774b488eb6d67f67c2d0a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/busybox@sha256:03a2d7272abbc5219df73a566aea5275754048cabb8bf79ecac48f40b06e72df |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/busybox@sha256:45e56c0e8faae30ad2ab7a170bc5a6012852896e1d618667eccd9ce69d4cfdaa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/busybox@sha256:e8149a0a3e623daf06478d77bf99342d13f8f335486171c387dd33846a27c691 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/busybox@sha256:5f3b09d222b795228355bfd95b85e60ad8a6ab7cd26f515b9996a47b90cc8dc3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/busybox@sha256:9e835664ecd73cc1473f14d849163d90ddc01660b0a167843de57f7dc69e49e5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/busybox@sha256:1dc1388dc46e46bb2943755eefc71a99653159c3aa810b3a4c9c7b333f927250 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/busybox@sha256:0b70a53337847c7074f39ad9478686aa65ae64fed08c7d135b58b5a1d03cea0a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/busybox@sha256:5c136d5ce62ecdc0d59271d0c8b8a48637b10ee5c3ea11069361616dadf70f77 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/busybox@sha256:e2863f616623f9c9e520933d10e23a091c0ecda70e5f38786170c4d957be2c5e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/busybox@sha256:580a38a056a1f3782377bd3d26935922e3e81f7282485bb3b1c33d9a58bc990f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/busybox@sha256:db489432ff1c5bef125f931126f95751ea628ae07b62a55b94ff96af6539a38a |