dhi.io/jupyterhub
5-debian-dev, 5-debian13-dev, 5-dev, 5.5-debian-dev, 5.5-debian13-dev, 5.5-dev, 5.5.2-debian-dev, 5.5.2-debian13-dev, 5.5.2-dev
sha256:f1ce9a14bb315524f40873e5a639d5529af634bc7cc639c65ea0a2284a3a7c98
Manifest digest:sha256:fa8fb5195825977fb006cc6da822710d40b85486cd752df03504adc3dcfef416
Size
85.66 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jupyterhub:5-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jupyterhub:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jupyterhub@sha256:89c369b5f82a8fffe8176f6911aaf2f500e947ba031a38d90386aea1f1a93b21 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jupyterhub@sha256:54e944dad7663a868365c6c9078caf443b9cf513ed994a210f6ea1f3e42531d1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jupyterhub@sha256:085f46fab4a28d1868cc37712edaef3c3165d73384a631855f4db23840bff648 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jupyterhub@sha256:a241cea3da2db668d126c2e7e58bc60da0edc5f88987f6f4ae223faffef89db7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jupyterhub@sha256:df481fd11996c9119d46e6c7d76cb16b837d623a26c79a63f7c0af2f389e5b49 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jupyterhub@sha256:154027ea1a4754d47e13af931e2e0dd2ee95b0e01ef3a365dff3840a07f5fc96 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jupyterhub@sha256:4dd5af7c638dda88de1c1f631e1b866fa5e35641fe08f777d1d4dbcd413dd07f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jupyterhub@sha256:739c30033b4bcb26db6b3c64ed1257883f134f3636ce67a610b32ad6479b8107 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jupyterhub@sha256:eed616ca097590a92c2eb545e1f58d28f5b8e3eeb885253536e0e5570bb11191 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jupyterhub@sha256:bc6a5be63fb3aede5df0caca565368246fc47b5afc61a4eb5e14e35dac3d33a0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jupyterhub@sha256:ba924c333f1d23326569c53004517eed623b8df62ad010a2b452aea9dc3bf520 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jupyterhub@sha256:c024b1e22a3d2023ff96171f4017f2816278738282d0aa4740e48cd52b25ce7c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jupyterhub@sha256:458b92e789ce8b5a698d029bd5d704e2d3d96091a7486beb3d1c6d4cc4131a31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jupyterhub@sha256:9bdf314bbf1d4c4f8d5c14ec53e7801f5ba6ac2d8999eeca8001fc62e19e12ac |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jupyterhub@sha256:8de6a2e91721a38d11ae149747a3eb2dbe0156c5efc5c1cdd9d81974ac547722 |