Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.37-alpine-fips-dev, 1.37-alpine3.24-fips-dev, 1.37.0-alpine-fips-dev, 1.37.0-alpine3.24-fips-dev

Index digest:

sha256:110f4debae2f3a2006dbb51abd2bc3281517f71af007febcbf088204529d1e9f

Manifest digest:

sha256:ab7fccb173f46cc8247a5ed547b92727e0440dfaa5521a84e18df850706760fb

Size

4.23 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:3c66e14556d43b4b3b436ec8619d9f5ebd06cda3cb53ff7aa02bb57f17f178aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:25636e75ff6ee89fe531af7bbfec3987148322adbc0bf61bdf31ff0febdf737b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/busybox@sha256:e3f620a4652afa2cb07dadba4dd32864a1a59b75a694feec0c4b92e7af8e9751
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:511c3fffc9bd3e5a26b81187fc49a6656dbab54b9dc0382441eb90d05f99a2b5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/busybox@sha256:c9ef48d619077c2a1f375ffed1e833759a7d8b7aa2b96090304438067c12a7e5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:62107c1b6f6b8456d7c975d4e86eb3e30b52efe6f0fb39fb436c2a3234ae18cf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:ad131f8935bf86c30b7f429032b563aa46898ef0e8912ce3429d886803f03b16
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:d146a0aff099d24f524f1ac2a018448099f9e92807bc288aafe3e739fb17f132
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:7a963a40ab6d0e84214b0d44264ebdea95757727fd1674cd6cf5714dfd67265c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:64ee2e2250c95c9442528f1987d8bdcfad2886501a7dc202f123612a2d22ced8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:ca1e2376a8aefb0a937b0966c7bbdb3c5b337fb9d2731f1e7a1ec536fedfcc1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:e7c96e569b22adcaf22604d4b360bfb386e89dc167e2cc54e16db33386a12944
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:770272bf7eb5d725bc9e9c0ef9cf9006f8dc6aeedbe5bd54603ed0379da70f4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:55cca4f3617b71d26fea3ab067b50ca96af5b5f7d3c575ba5732c055e0b1bfec
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:d85518bd785819dce3990a34c087064a2afa823fffb31b6f8d18f7f61c55b2e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:6ff62f40a9826248f0bdd63b7cb36261df16486ccee546489a018b91f305ef6d