Sign inSign up
BusyBox

dhi.io/busybox

BusyBox 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.37-alpine, 1.37-alpine3.24, 1.37.0-alpine, 1.37.0-alpine3.24

Index digest:

sha256:cf19544e3830bfd972cd1ab793be113129c61f214583648d590289eaa938ce5a

Manifest digest:

sha256:a32ddf2696a19b80f59bcd855657062bda4d2a24eaa794148fa5fbd450ce7cf7

Size

1.00 MB

Last pushed

26 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/busybox:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/busybox:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/busybox@sha256:2ce6ab76eb8b87d700adab1f48d3b5cd2a35fde39e0cea4a0557e28ecdfa6d46
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/busybox@sha256:2b42d218db4836c50b1c298df50e2c919939b06dbdb4071497bdcf68705ddc62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/busybox@sha256:73f43e276e62d42a80f8255bb3394a2d2489096a5904b20f23120411b1bd9fa6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/busybox@sha256:db1b0eea9d0f2b86aedbf2d144fe0d2bf67c528d54a9436f1ffa8f3ce5a9b912
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/busybox@sha256:1f29c88b7d47541012ab1a23e6fd6dd74548637b2080ab69f6899d519dd54a7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/busybox@sha256:c3b47ea8de924da545d10a30b6e74e1e339f43e47fca4918fcc2aad03333e0d1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/busybox@sha256:2f0a79b11592f8ccdabe1401cacbdd8df2c90f108052b0c4106ff3510902a2d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/busybox@sha256:d7eb4011f83fb57a29b4d6a32ad69cc66359938b606dfc88d8da3226d96bd8dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/busybox@sha256:dc95177217f1efbc66f4a6c80ad778dacfe7ebd58782c39d647ebf4bb24266c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/busybox@sha256:1814474bcc2316421c22e18c5f8794e441f4d5f6927c7d8ec55c9e097c73d337
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/busybox@sha256:8be064ad1cdd9bbc0b6c4ce21dee5f0cf6c993c948091a502dc837af2ed411d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/busybox@sha256:07b1923995b0f87f14ffab036a0806c44aa02a37a385f90206d9a841bf5ea1db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/busybox@sha256:bd13177fff96808ace2c08ef6b88246cbdeb2246b506d724cb7ad6c244150594
SPDX SBOMhttps://spdx.dev/Documentdhi.io/busybox@sha256:84af7aad6255c1a8735ae11da4d57c12e84979343edafeabb67fe0e1ab367d63