Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev

Index digest:

sha256:ca6802298d7d50d174be161d44eaac3e8b5c6d72369e9dbf58c3a3c749861aa3

Manifest digest:

sha256:f2200c0f79bb1f6f8a936ae4fd7a31d692d235e462d8c1e92bdf5dc27c15f29a

Size

85.11 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:ec91ba0342d7a0f7d5624f0e31d0ac8a5df4e915adddda77d63cd2bffec63030
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:8770f6d5211ca634cbd79cb82c7bab38e7e8a99ee0fc4d6e606c65581a482ef7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:071e990c31badeb3d02ae13496c7c18574cb37cd22f7e829a77e229649085105
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:4c6b32dc71f326c594939e88b434bcdeb3c8db43ca8a8078fc8499951e2ea4b9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:3e4c52233c92de8044644ac8817d0d9ed03e887635d9a59a399af4ccdb5bc6bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:cd137027a0cad9082b35146de5a3abf0660f4a8fc42b396795357efcadd47f07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:96d2bbb25fdab2dd318071ba3087eaca518fa8634b5769287e3a338658b3633f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:27ed54c505329334d3ece16fb8d167713ff22896a17d8e8316ba8001e2538ee8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:5d3197094411245febff628bfb11a7af0dc1af2fb7ffea6dff45313ba437a43e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:b8bff8b04d34525c2df090bcda70f9555266f896b90c139e981dbaf7a4cb5e94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:7587994ca9267584975ac3490fb55777aeb2fc0fbd350dad7ec03ac49ba6a0f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:3b5b71ec5d46f209fb78b4fb12444f5532f491fc33f3cd1aea1a3e0d1de9d145
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:b09c0d5afd88bd342a4d423b228d62bf870cf8926decdc735bd01fd23bec8b30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:de380c953c7d13f72a30612f25e702a50b195853e31921aed108a6df850d1a4e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:a3b33b414d6f5368d9db503665a06dc0b051aa8a1ecfe8e167a5b65895da75bb