Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips, 5-debian13-fips, 5-fips, 5.5-debian-fips, 5.5-debian13-fips, 5.5-fips, 5.5.2-debian-fips, 5.5.2-debian13-fips, 5.5.2-fips

Index digest:

sha256:7eb7d608c73b50e99d87f2d6528ff76ffe2b548c5bfee1e0fd98cb0ce6206189

Manifest digest:

sha256:be3b7c60f984e0ffbbecd986eb086cc88157e144829028f2cee9501ffaee210c

Size

72.27 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:3d0d787548af2626fb2511d2072f2f73009f3bce7e6db02f439b5567eef9f42c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:d668c497d5558ca0c8d60a452bf8ef763e04855e6ade29e3f627ab9e61ca1e23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jupyterhub@sha256:e6d1f24cb6171aa9394ed90e4d810c35f0402ecbbda8148912c6ecbcf98734a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:938a34508c7bae47f9f346e56d25e525fec0a6bde07f0a0da90b8b8424d586ad
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jupyterhub@sha256:838ff9deae7dfe7d2063f089275adffbf6e6bb81670bfba44a32f46fdd5364bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:16729842794283c34e9370018dd87c45e50ff672545deff04914faa280b02154
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:f2eef6e87daf66a1e3b4ea544ec4e96fbfb162ae63c81bf3b0ce8ac618336fa0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:12abf322197216dfb24cb593a6a0fedc8f6321ad906b60795cbe844ee8c445cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:eb02069a2373cdaa3a3fd80bc18e7964f0ca42fbb518ecc7f75b283d9eec94e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:6071865f593dd87aa1a5c02aa4a6308dffe81e7ca0f35f67d029ace06afb3671
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:1a20286b3dcae89cab3d5dac33e15996a7294cf268212f51744f887b835971a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:357d72a6bbb45d7b0908713c0de79d325162d4845858936bf751e16baa31ccbd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:640a182736637c6fc700548a4efc138fd73fae9172a87cb1eacedad6cbe6f273
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:07ab9f8ad2e92289e8e9f4a96bf289aae679dcaa08b8464fe51227cf39040c97
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:582f6b00f2b54f45c074f7c96500c45b29159953c7d13ec0efdacd892580ab3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:9a82d4e57262430280348afeed2724855bb3e5eedf90320b5044a4557098e1e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:1df2a215f7c1219d062212b0647f34ad509a60598b123f9d5a9256911fcf475d