Sign inSign up
JupyterHub K8s Singleuser Sample

dhi.io/jupyterhub-k8s-singleuser-sample

JupyterHub K8s Singleuser Sample 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.4-debian-dev, 4.4-debian13-dev, 4.4-dev, 4.4.2-debian-dev, 4.4.2-debian13-dev, 4.4.2-dev

Index digest:

sha256:95036d8839f0965ed2246afa823610bc498df897f3f84bbdbf460f9f516396b4

Manifest digest:

sha256:faa03a7840897fd26ce39a281f2fba101112b571258e3149068d31c5f367c098

Size

115.44 MB

Last pushed

2 days ago

Vulnerabilities

0
7
14
4
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub-k8s-singleuser-sample:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub-k8s-singleuser-sample:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub-k8s-singleuser-sample@sha256:a6791f075ac57a023fea24b934c90e8a428f93fd7cbb7e025561e317c9b50dd5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:6c171e05ac84ecea13572f50b523c056660ac7adb75f208f04c2790322608b1d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:a77d2ff8d76c361bb40c44085a81a230362a7b16496ae48e532f22c60ec7c1b2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub-k8s-singleuser-sample@sha256:d6b9e7f019e045c4967a74b080c7cd15e0fcb45367f4563dd7b7faf96acb62ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub-k8s-singleuser-sample@sha256:d6643f216ce82dd61dcb877c898d3775d27c5ecb31d557b485155f24c4793174
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:4014e86780ad349e1f5d8a306d22718069b90b13b7b587e6be971dd2c234991e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:9ffc34720305154a56e49e77cd8f445ef813d3072e203373c0bce77dc5c9162c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:83fe8306e121774f178ea62140352155066b760ad4824f921fd561fd0a347b5a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:555c293cb506849a32774e3f4f582c04f5af2dfa4fd4a38ebbbe4e19ab675bda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:7ebb3d653209de5ec3f2aff8235e75d0ac2bd178589f574c1fb440428b431e00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:1334f850cb97b926b6cf1d411ea1f45b97be1c57a0e9d03f8c310523819936be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub-k8s-singleuser-sample@sha256:eaf53a4bd4164bf6edbfad6bac6997402c24a527bb26089942c2cf008e6b5b2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:5eb6c01188484b77f0e5db7f43b3fa844b3fe98751c698f37515be9d20b119b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub-k8s-singleuser-sample@sha256:f464c9f16ca60b96a8f58d2cbd69fd51446b5ae88e46e6600c4ba65d18ecb4f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub-k8s-singleuser-sample@sha256:e682fcc86af9174de4185bbb46cca318a07321bddbf0d7059657683452890c46