Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev

Index digest:

sha256:976073343ab5787c05bea7c0f967dbfa55eaff9348c5a3de7e1a64132c0124d9

Manifest digest:

sha256:a65268bfb3306cf09d3f2928fb82b0f95c87371733a2ca34373f691f60aa6038

Size

85.11 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:25681cffcd32aae8f439cd3d26f1b797fbe2a23044126954143b6dd4d8a1f2d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:89d010165f638aaaf785b4d01be5d696db8c7e3ee5ff59a8b7fc67b3b6470cba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:73cd02f25ac7108d6694ce7a24658e70762c68ac52ad3e7b57ac24bafc30254f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:62bf8b493ac56befca9d867ffa8d008f1cb0c1ec0eafd47e3f679a65e548ba88
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:51eec6bcefc9a965af73a3a6fc450fc160a9d80168d803fb71deaab72edaf1d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:15f091e590edf9a02812595ffd4053a3af4ffb06d7da11f6854664fefcfbdc18
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:ce37b6c059aabb95b892b09ab1b005ee2563fa26f84a967abb41b12cdc1eedc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:1d46ff87e6ee99b9d0f808afcc99e8ae0c3cf3a2c7c9a4c8d4fdd492c2571873
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:cf877b15cd37a5d54c371e3712b25b48f4b6e8c7751a3f52c10bb7cab226306b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:7c0d71a719879e55087e4269a5cd4e28cd98ed6d764715eb102252b24d8db17b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:3b0940a51752d4255464220da4f3049a2784120d1856b3a2dfc98558019e15eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:7ee9b41cc4d2b334fe0c05e7252331bed9d313041f74e1fa6bc5bb808922a895
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:2ebed90bb01d46605c265cf2259d7b798fedf32b3ef685269a88332f8a399eea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:8dcf23a893881fae37831888bc719999b0219408bdce7e18bbb65a1da33eb6b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:d784b857f8487b11a3f6934eb028463428d173691a2d9c6c7a31d53c77e57a73