dhi.io/jupyterhub
5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.5-debian-fips-dev, 5.5-debian13-fips-dev, 5.5-fips-dev, 5.5.2-debian-fips-dev, 5.5.2-debian13-fips-dev, 5.5.2-fips-dev
sha256:43d3a1c93e4ce86e344fdfeb023272dc04e24b29e41d1f6fccb873c66834ca2e
Manifest digest:sha256:18bfb35b36dea879bcec9340aa64660cd15ad5815813cf0adfa04720de53f468
Size
85.87 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jupyterhub:5-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jupyterhub:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jupyterhub@sha256:1fb6905ca8a1113f9befc52206627e13e73de30071274f9418936a5a977bd18d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jupyterhub@sha256:b97a1af33fc4f1cadf3562fbd1df55f7238161148cff7b341dbb170f9ab58722 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/jupyterhub@sha256:3c5ed541af2bd413cfea718e810faf3f185116e4b3a9c0cf81b9fc5567e05730 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jupyterhub@sha256:2d684aa2bf9fd677aaa815ed1a44b89a66048b8168787ee6d78947056de941a3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/jupyterhub@sha256:5f8cd13c57e08e473d227dc64cadf4b03bd6433c1295c16fc335b9ef13201961 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jupyterhub@sha256:12abdb44a15674c84894fafcc9280c3841e5ae4adb56d3f22d09a55df63d0d1d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jupyterhub@sha256:8ead3bf1e4e4e63eb1f3019bc2cb4fe4cef31ce19dfb301fc78758f2f0bc9b73 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jupyterhub@sha256:3d0527990bc03c70bff89a1a4eddad095bf9a592cc7cb702358fd8177d158f25 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jupyterhub@sha256:0f0c7f21f214e9d935fed9bfe1ba40b97d897941edcb25b6e7881b4f07b012b7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jupyterhub@sha256:005dc65ff0c635b1c8f5192aae06eb5d66fa0428a503198c7c7134e72fe19636 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jupyterhub@sha256:7628be918e49db6a410f0373e96918a75e27dde1d7497565113a15e51200ddd6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jupyterhub@sha256:031e2de5f686e4edc5aa98433558a8e7c860a993306af6751fe6c7c6b4599e11 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jupyterhub@sha256:d1e6dc73dbeaf38706c65a13b596a1e970a8e216e1798c960c5117d3eda2eb96 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jupyterhub@sha256:04eadc7ae2a41b7647343e57dc4f2bca178dd1d3fd8c843f9489b5dfc78b42c0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jupyterhub@sha256:1251cee2a14e22a947e57bbcb2351a063a96bdb3f20f4c7d9757497b71110dcd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jupyterhub@sha256:49835c493cfa34f348bf45d3ecf27c210fe8126229e8d970481e8b42a81985b7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jupyterhub@sha256:c1c0f97a04a886e97b047f49ae805016adc810e51804972262a083f0668d40de |