Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.5-debian-fips-dev, 5.5-debian13-fips-dev, 5.5-fips-dev, 5.5.2-debian-fips-dev, 5.5.2-debian13-fips-dev, 5.5.2-fips-dev

Index digest:

sha256:43d3a1c93e4ce86e344fdfeb023272dc04e24b29e41d1f6fccb873c66834ca2e

Manifest digest:

sha256:18bfb35b36dea879bcec9340aa64660cd15ad5815813cf0adfa04720de53f468

Size

85.87 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:1fb6905ca8a1113f9befc52206627e13e73de30071274f9418936a5a977bd18d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:b97a1af33fc4f1cadf3562fbd1df55f7238161148cff7b341dbb170f9ab58722
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jupyterhub@sha256:3c5ed541af2bd413cfea718e810faf3f185116e4b3a9c0cf81b9fc5567e05730
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:2d684aa2bf9fd677aaa815ed1a44b89a66048b8168787ee6d78947056de941a3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jupyterhub@sha256:5f8cd13c57e08e473d227dc64cadf4b03bd6433c1295c16fc335b9ef13201961
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:12abdb44a15674c84894fafcc9280c3841e5ae4adb56d3f22d09a55df63d0d1d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:8ead3bf1e4e4e63eb1f3019bc2cb4fe4cef31ce19dfb301fc78758f2f0bc9b73
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:3d0527990bc03c70bff89a1a4eddad095bf9a592cc7cb702358fd8177d158f25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:0f0c7f21f214e9d935fed9bfe1ba40b97d897941edcb25b6e7881b4f07b012b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:005dc65ff0c635b1c8f5192aae06eb5d66fa0428a503198c7c7134e72fe19636
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:7628be918e49db6a410f0373e96918a75e27dde1d7497565113a15e51200ddd6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:031e2de5f686e4edc5aa98433558a8e7c860a993306af6751fe6c7c6b4599e11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:d1e6dc73dbeaf38706c65a13b596a1e970a8e216e1798c960c5117d3eda2eb96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:04eadc7ae2a41b7647343e57dc4f2bca178dd1d3fd8c843f9489b5dfc78b42c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:1251cee2a14e22a947e57bbcb2351a063a96bdb3f20f4c7d9757497b71110dcd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:49835c493cfa34f348bf45d3ecf27c210fe8126229e8d970481e8b42a81985b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:c1c0f97a04a886e97b047f49ae805016adc810e51804972262a083f0668d40de