Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev

Index digest:

sha256:9878546d45e8ed31159a293214cd2e0e33d8da42645c04f8c9866d1f02f49a9e

Manifest digest:

sha256:6e0051c4b60c42f76f66d84b04de7e030fb0f93b9dd06390d07faa57d5053bc6

Size

83.96 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:8165288327b0563f70d478b0e8e80716fd01f75eba856803153c75ad79edc56c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:1db50b14b46343a9e95886b1721f564c1164e7423a8203c2648906288ea4caf8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:88df7cd62b365cfd0fe8a19e8824065b0357e2c2b63ee8fbcef8e955c4d4c27c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:dc1fa3562120b149704ac3c563e8c3f3a47197c00a39924553218c952e94d538
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:1566de8b782b2627a54634f2f4dcda0f383a3f394add01105e7abf2da270c3aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:b98f92165fb66ea48cffabcc32ed18b9023cbdd92b19db95eacdc1e92f3b99ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:a7ccfd2c062b73f1a79943fca302024e7d9dc27ffa64adb0522da849c2adfaf0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:a0501d42232dcffd6cf1c1f10dee7b4c55634e87f24f34bf1a11c45bbab625c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:84a0a607da78b8132b90bcd4d83d71cff84227c62d79e4d744882d3f3f16059c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:bb27cf0338baea6d512c1aec4b924a16d3e4003dd164728ee30540d5aaac0f71
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:b5d43b0fb9a3a3da036d499dde3b51dfaa95725e2c187c4c249e1e79eec2b517
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:587eee68236bb9e21847c60510bc4ae943a1fb4ee8ce457ef10ffef235762b40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:a0f9ab61a1ba3f062dcebffd6a889044e85d71bdba594e6c54a89b6a03d5aa33
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:caadab01cf39c23c944ede247c75ea87121beab59ea6a9f41e107cc9be34489b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:42fba3a3aa39fe2392d27b8e2a3911bde310e6ef71b13b2d8f73401678878706