Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev

Index digest:

sha256:20e1ba7d6a0c5e1f6e67d7714e265b4a4837c6fac3200a6edc6ee918368b85ca

Manifest digest:

sha256:c34e2a98574c518f07a8c4ba6185fd0e1507a332600199437c51bbff78e10f99

Size

85.11 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:7f17dbcf3c3864ac66a44cc8244cb8d9a687cb823f91caa0d04f0e885d763ab5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:5e2ef7501af5d21aa52a0141fe5c95a60796180acfbd5f322fbbcf87868a1975
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:5e645cd19b58a5831c3a6a21d646d2accfcf21fcfac0709381d1a95344f41949
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:e50b3c758883ba6b35f0223c0a51f78a9fcd8c47bd7e69b393afe1e5164db765
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:6f22e1bdb3499ac479438f7ed7df4f9c2a65d0c6fd7989664aa3746feaf37868
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:756023b6eae8df6491025223462b467b7face31d88fae38ee67d944c1897f46d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:18aff5da387be87b0e91576da1d1f0d845ee24e84d8b1f04a7d162cc8500cc86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:dbb21ea97ae51dfda96613dbcae321c842885d1745f60318d1324074cfffeda3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:660bcf510064599328fd509c27145fa63648f11b0b885c5b54098ef022c7b3d4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:bd24338eca068322a27981d1f24fc60fdcca90c79ba1f0f5b2f2050b92ebe1e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:138892f5bb5bc27cb483b95d0c71bf47e9ad762d926aa6d62365b2d90f9e879f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:8eae97610a5a8244884a5138e60bdaccee35425451786b82ce6849a4eba37e46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:0c6f20b2704837bce93289adefa6c61f19453c24a57d6bfe600abaf45e3e4ef6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:236b88c9df1e5bd06204360761e196bdfef38812fb384c734912da94a31130cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:46c7756515b484aef2068f4cf8296fcbc9b578518c311f14ecd076b2be589680