Memory-Safe Userspace and Build-TimeEnforcement with CleanStart
Replacing BusyBox in Container Images

BusyBox ships dozens of utilities inside one C binary, so a flaw in one applet exposes the whole userspace, and Alpine-based images often inherit it without anyone choosing it. This whitepaper explains why patching and scanning leave that structure in place, and how CleanStart replaces BusyBox with CSU (CleanStart Utils), a statically compiled Rust userspace. It covers separate development and production images and the clnimg build checks that fail any image containing BusyBox, dynamically linked binaries or disallowed symbolic links before it reaches the registry.

