Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.5-debian-fips-dev, 5.5-debian13-fips-dev, 5.5-fips-dev, 5.5.2-debian-fips-dev, 5.5.2-debian13-fips-dev, 5.5.2-fips-dev

Index digest:

sha256:0030e81e664aae203af4409a2047d955e2168b9d554c48d1634d67410c266c55

Manifest digest:

sha256:d17c5756ffe5239ee6f7a7548fdea0802b3a235e7f1c6e442dde85e1ff08499a

Size

85.87 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:c08f8daa9b2cd8f61325e8a83804b916b0481c121b7308c0471f3c15affe3e45
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:781fa2b93157f352dec0f86082867dbd9cb36a40873acb9ecded3c3a939e0b9d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jupyterhub@sha256:ade851491eb29a7afbd884d3d065bc9c28cce015a569f50a9ecc171c39c76ea7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:24cdb9813727cb61e8e731b6327188f39cc9c866288515db92bb95aa15f84e80
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jupyterhub@sha256:7b6f0352a65141ce5e58176e4d7f2fa406aa0f040f117795561299881efd9e4a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:8e28817bb1c3d109efa87f40c6508bd44f00d66ce1a75e19246118fa07a7b9ea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:a1b5b153bde42a6bcb3eddc68539d44c052fa7e78354a21a566f1c8c7b0e8430
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:679da6b48a15786d9200d4677772d57686b121a2fc4893a4a9602b60f285ea76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:8c3e863883584ac4281ffcebcd3adc0caf0ca18b817f5ccf5c386cc7b8ad0a0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:e6f1c42afec2a7852fd4e80e2a5b87701dbf10d6af0ec477bc5d64bc3a091f36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:770521e8431c467657c4a3c19e7eda4478c3d3782b0f34d800fe254dd0dd6334
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:66d04f2faa29b5171178b2f2e57739abdd2fe12985edf3bbcee321a29abba0f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:c8a12a1498fda0ac7ff9dbdfede1f4f146b3899a4e6a7d217b072f763ca81686
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:874674661ebfb80f38f64faa365a61041e04e52b34ab81a73548f9c2a3a40ce7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:d105b737f4c345dccbf4630a1e6e816bc1d3c07ad949c526f246d7b5f53fd2b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:d8eb50db4fd5f6666bbe943b2c7c657e0ce45a040b591a4862e5bc4150b0a5f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:d289474e7a058c373849f41a44738b4a1a521cc276c2f7e4c7e42d270413ef7a