Sign inSign up
JupyterHub K8s Secret Sync

dhi.io/jupyterhub-k8s-secret-sync

JupyterHub K8s Secret Sync 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.4-debian-dev, 4.4-debian13-dev, 4.4-dev, 4.4.2-debian-dev, 4.4.2-debian13-dev, 4.4.2-dev

Index digest:

sha256:510ed64a003b1a8a18b7bf4e313cc7f86d0e954792e76923287b167220e7c011

Manifest digest:

sha256:861e4bb3b8ad68b41f5e79db1fd623d9484ce79ca870960d19d51536748b0c78

Size

62.46 MB

Last pushed

15 hours ago

Vulnerabilities

2
6
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub-k8s-secret-sync:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub-k8s-secret-sync:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub-k8s-secret-sync@sha256:356902d2ea604ca75ab7298a163fe73590ae36acb3097c78bae43b729b9cb0fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:60a023c9ccd98839a0ef9ce388c7bb57d3c89686cdd0b21b9a0f3aabdda697bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:0a58ebc08b0bd8a3fe67bfb343223f2ef7768898164fc250444469585c70304c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub-k8s-secret-sync@sha256:617ed2250d0fcae88184ae1d5245430441232b100c26105de3a00d2b8e039232
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub-k8s-secret-sync@sha256:84f602393c59f4ae5642e68a0e25422e987dbb83ccc0474beddea4161073c9a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:710a66dcf2ce48da43b8369db82bc0cfce53b7f894a524380875835fd9431e79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:c47e2961d3694b56bafb29b0a78291f5e39ff55dbe7db7193d4c4028ab0eaa67
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:c7daf6f95341b9ab0b1620329aeb797ec8580b060c30e29513db7a0bd8b4879b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:bdea1fcfb23c24c20fb281ac7e33daf3e58abcdce5066456ba426af7c5f86608
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:8fc9707ae3f967c40960d7f13a965e3e8ce9960592845504e50ed2876e9ad954
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub-k8s-secret-sync@sha256:4097b4adf410f55872cc7a22ef0e947a51d67915c2fd6659e799e4f15835af48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub-k8s-secret-sync@sha256:976d70965373f4359d0ac8c9a2a847dfe3d810345f31176b6ac1f0ce1cdf37a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub-k8s-secret-sync@sha256:aa94fb0926c468333d0e539d567ae5946afb019baa44934a465c60cb0340278a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub-k8s-secret-sync@sha256:afcadfe6348521270f46bdd124ee88c247e11d257630779dca4e805dd08a81f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub-k8s-secret-sync@sha256:4c90e4e9132038aff949075436619f974800cf9a8fcf53627f01fe618971bce6