dhi.io/jupyterhub
5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev
sha256:20e1ba7d6a0c5e1f6e67d7714e265b4a4837c6fac3200a6edc6ee918368b85ca
Manifest digest:sha256:c34e2a98574c518f07a8c4ba6185fd0e1507a332600199437c51bbff78e10f99
Size
85.11 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jupyterhub:5-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jupyterhub@sha256:7f17dbcf3c3864ac66a44cc8244cb8d9a687cb823f91caa0d04f0e885d763ab5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jupyterhub@sha256:5e2ef7501af5d21aa52a0141fe5c95a60796180acfbd5f322fbbcf87868a1975 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jupyterhub@sha256:5e645cd19b58a5831c3a6a21d646d2accfcf21fcfac0709381d1a95344f41949 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jupyterhub@sha256:e50b3c758883ba6b35f0223c0a51f78a9fcd8c47bd7e69b393afe1e5164db765 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jupyterhub@sha256:6f22e1bdb3499ac479438f7ed7df4f9c2a65d0c6fd7989664aa3746feaf37868 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jupyterhub@sha256:756023b6eae8df6491025223462b467b7face31d88fae38ee67d944c1897f46d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jupyterhub@sha256:18aff5da387be87b0e91576da1d1f0d845ee24e84d8b1f04a7d162cc8500cc86 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jupyterhub@sha256:dbb21ea97ae51dfda96613dbcae321c842885d1745f60318d1324074cfffeda3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jupyterhub@sha256:660bcf510064599328fd509c27145fa63648f11b0b885c5b54098ef022c7b3d4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jupyterhub@sha256:bd24338eca068322a27981d1f24fc60fdcca90c79ba1f0f5b2f2050b92ebe1e6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jupyterhub@sha256:138892f5bb5bc27cb483b95d0c71bf47e9ad762d926aa6d62365b2d90f9e879f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jupyterhub@sha256:8eae97610a5a8244884a5138e60bdaccee35425451786b82ce6849a4eba37e46 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jupyterhub@sha256:0c6f20b2704837bce93289adefa6c61f19453c24a57d6bfe600abaf45e3e4ef6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jupyterhub@sha256:236b88c9df1e5bd06204360761e196bdfef38812fb384c734912da94a31130cb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jupyterhub@sha256:46c7756515b484aef2068f4cf8296fcbc9b578518c311f14ecd076b2be589680 |