dhi.io/busybox
1, 1-debian, 1-debian13, 1.37, 1.37-debian, 1.37-debian13, 1.37.0, 1.37.0-debian, 1.37.0-debian13
sha256:abcd06d567c6ecda4aae78cff5334a231bd3e663b69b671612566d4a4c949899
Manifest digest:sha256:dee85c9b0f115b1c142799e1bc00c078547e26d03474202e2b5173b5e70093c5
Size
4.32 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/busybox:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/busybox:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/busybox@sha256:2716d1aa3f73bcf49aed7624406cae0ce8f7db73ad17d4a382bf2e7796c5264d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/busybox@sha256:10564243d1c87619ec626a8b00972f3bdd16f1e7b5cea7cea06b313a5edb396f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/busybox@sha256:ed314d294d0e2fce730cbb8873b20bc5f5f27cf521f64cec624e2e8c3c3bbaaa |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/busybox@sha256:48d47fa972fff1761505ad68824216d8c87668da28a32d3f77f7aefde7db3d03 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/busybox@sha256:8d7726255b039d92cc2a4e8ccb81ad3be0a67e190de4d4d024ad1db1a59492bc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/busybox@sha256:17337b001b0b8a2df83b60cc3b0fc26fb439fcdbf2723efcf3f8f79292b42fbd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/busybox@sha256:070441e23295e4c4306cb2a9059497b7fd15f4824df23e7a00f0f2c910ba23ab |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/busybox@sha256:b9ce1d5c8c5e57225442e2ee7ea345b4db2b2097a5dff26c14920e840392111e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/busybox@sha256:d796bbe88b3cb2bea2dded28c3b58417875f360d4943490a21524e1d2086fbd7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/busybox@sha256:c953d3a7eda0dba611cbb791087596228bcdf1c5fa07fd5920e2dd43bb96634b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/busybox@sha256:536f65a078c387e515f5b21defc264a7dd4e1cb5c1e90f2f6410dc7107829f54 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/busybox@sha256:5d342aa2d5dc05a215213c75b2df4d6e4a682fd0431dc3ca8373051bdfeacef2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/busybox@sha256:bfcd3936f96e67c7232382e6af4b0d5cc7a61c768ec3ef52c97d1f2f5310299f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/busybox@sha256:c7336a198ab1abc0c47c47df340fc5858bdb525d2dc04ede534e731f52b25af8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/busybox@sha256:6730ec0c17ea31a964960fb13843c9fdc365ae8e1ce8f07e1d819e905cb4465b |