Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.5, 5.5-debian, 5.5-debian13, 5.5.2, 5.5.2-debian, 5.5.2-debian13

Index digest:

sha256:c69912b4c8fa11736eaee3452ac5982a98b6d8e3015e692c3c4a0e008e769a8f

Manifest digest:

sha256:55b818f9dc8f297eadfcf2dd54633363bf5c371fe4bc93e9202240326b8d301a

Size

71.49 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:70a02f543d55d6c9b4efe76ca33dfb608fe7eecc70708b4797c474c6b05380b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:7039512a3e77d02b2f359aab1c01adbca85a20000fd413e94692301434e62267
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:7dcfd7723ef40019aa1df4eada32d3e2dedd6ad2d5fa93d3320e2b15400fa327
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:112fa8159992534aaf60eec90e1eb97c890e57dc687f2836b12ea22918fd7907
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:65a0ff99b6cd154edaef3285fc4261b76c40efac3f4fff68d8a17c2ae0bad0fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:3f88807b13c2b403aebe138b62e3db17a845407db5b1e88d813b57c719832f93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:613bf8c4a7709723c1b8f8d0abec2b4af5bb503766417496fa0d6487c475a46c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:3c22d60f156cc3077f15ec0f76ea1731eb57756c780fe69fec0948df61f30f6a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:014d4a1027e36a8070ecb6eac64a9d2d4270bdf747ae2d07694dc61dfbc218c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:209de41df6ec48cb9631e62f3d2a4938b34727eae8b55b0b98444e887ce859c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:1ee9645fb4d4f70af05c2eddfe2d81b452a7514d80ceb9a1c26fa81e9a30e2e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:f393e3eca71fd1024a0d7ba0369cf5c6e5de60888c34eed43642d172f51258f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:0dac619175eb0472a5cfe89eb18c4fc9a591a0693b9109043b62d940dac0db11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:705a2bf62f660df7d9fbde04d8d911affe0ab9515d31604f89100a6b5e060c98
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:02b2a094bf2a606367177fb3878add629c5e1100958c83b1f42349254cb97ee7