Sign inSign up
JupyterHub K8s Image Awaiter

dhi.io/jupyterhub-k8s-image-awaiter

JupyterHub K8s Image Awaiter 4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.4-alpine-dev, 4.4-alpine3.24-dev, 4.4.2-alpine-dev, 4.4.2-alpine3.24-dev

Index digest:

sha256:884af82a279d0f61203c6958ba92d267c549ab2ff9afab4cc51235e9e8f7d40c

Manifest digest:

sha256:a5852e70c69bbbffb8354164959e5f1c679a13cc92cd916190641ce9115cfef6

Size

8.33 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub-k8s-image-awaiter:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub-k8s-image-awaiter:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub-k8s-image-awaiter@sha256:434d55635aad3281e091cf014c93339b652f136601ea64b4ec33ce8e73165b08
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:9a26367c848d809abec9d0b9821705fce3dc5e08fc35eb563b3e85bd3f51863f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:211e5fc2723d7e3c8a919f759c182982abba205f191add0041ead3c55c4c6e3f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub-k8s-image-awaiter@sha256:a4c331c32d9a2ed2ff3e58adfadd3a372b075c1555af3a9470023f6765411bd3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:852d3bf3c7ac85f7778508a2e416d4f08f9cadff54a9fb79a86f51e47e972f83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:0725cae2afbef26afaf082fa8773a92444635e16145595a64e9664341949dc08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:43627e0a02ebdbdbe064e4eb30350397df03b88be500edb85584e97846073e71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:e17e99fe46aa15cbf9a5759ec6697f3564a0069e136d018bbbf7f7d818e52217
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:22b049e8847b8fd9fe9cafdf53aed24afd62f365db10e3608d8e931d1ce90813
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub-k8s-image-awaiter@sha256:8d2b408cbac65f9624754792608d5eb3352abca7433b2db751824b8757ef2b20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub-k8s-image-awaiter@sha256:a0a323825fd6d6d22ce0edd0fb6f488da7410a534d4cb351aea252f448a07eb7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub-k8s-image-awaiter@sha256:5513bb1909aa579ad981b6f81f838b8fc000cab0428f5a1aad2a06999ba1f727
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub-k8s-image-awaiter@sha256:5d3321868af77ffe47ac6d432ea45dc4627de21971ab257c8149d5033e8f91e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub-k8s-image-awaiter@sha256:cf9429a2efc2315b1969ef2232355c914e3d9c57755f7c946a8b56e19bb0e266