Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.5-debian-fips-dev, 5.5-debian13-fips-dev, 5.5-fips-dev, 5.5.2-debian-fips-dev, 5.5.2-debian13-fips-dev, 5.5.2-fips-dev

Index digest:

sha256:ed2abfb75ff602a7c9fc2a84c36d6b1c6bb87df373e9e9593acc1c8e26578ac3

Manifest digest:

sha256:e15610bfacd2801b75fa850c489cc20cba5ea72cbab2c6467685367ea827fd16

Size

85.87 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:491c19925d1a59b1e5b966b1fd2975d4f80c2193f1cfc7f511a928f6e253ebc6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:e89c867a7503cee5b5768bdff239cd0424f23d79415733e74025e6e60895623d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jupyterhub@sha256:b23d2d83fd170622c0cb675c7d492eb464cbda4b103b9467395897b919f3b2cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:64470cc60e24a6f31ddbcccd05364d08b6487c444f06c9622cb10df36b8fcec8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jupyterhub@sha256:f184de20ea73043e8ec11ff411df8144282ed2e894b030f10fe384c804505a15
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:a5fdda94cbe3500cce9eb2c06f307543844763f5111d699fcad1a16b4df3497f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:fddb025cb07315321014cb5b6bcaf3ddbb5c22f7ff2339bfa5e2c7401823377a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:ffb95b40d5e86b203427bf19599e6f9587a3e51b7430d30a0548db4acf906f7a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:7f6cf133c9bf3c1d13898f6355b510971b1e52faac8526dded97dd07b834568d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:d4d9c6e0c83212d1407c0271b7c43fcb8410a33e2b6e10aa36368298d0b94458
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:ebb08a9430510c486a273db38a07749eb892b8c54b43c05977e89f75d17126b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:84dfdf6d0bd5ae3edf547eed6858320e1602d51f247e75746d305959fcdf457e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:9d65ee7b0b776a77f8f9bfd16f19db63e5ffb732be6933ada6a4bd5c269cf5f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:967248e2ebdc57a6f7ce4e614c3b7bf9da7a1bb98ba09bad082273a211c45f83
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:63838f9201c6a029f222a46cf540f9c4235453d4c5dccb655818abfe88b4a9d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:35ec0d224a73ed9d3e7f43f5b784aed4c73f9f4338e2449e107ff78cfe56f4a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:bf55bd5d24c1101f8eea28c9a75b6b42b5f548fe2a4a1f677268065e787aebf7