dhi.io/jupyterhub
5, 5-debian, 5-debian13, 5.5, 5.5-debian, 5.5-debian13, 5.5.2, 5.5.2-debian, 5.5.2-debian13
sha256:70c2d456d5dd66bf4f8552c43747b468d1fd8ec8c9921c97f602610ccbbd7841
Manifest digest:sha256:6c8c4783bc8a309de06ccbcb25abf4ffdebdbf4990042e7dd9cead7e1e394c8e
Size
71.49 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jupyterhub:52. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jupyterhub:5 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jupyterhub@sha256:4914270ef8dd10ce72733022406da32f04f330ac3a8526d1298aaa1181b46e4b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jupyterhub@sha256:2181156c558b3958d532dab6878e99d3fa160eed060716059a5210badf866e6e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jupyterhub@sha256:db25197dc59fe104b1d12ae5077bb8533eb9ac8715e1ed4efeeb5770cecf1bbd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jupyterhub@sha256:c779c32255b61bad56e77ef01414ccdbb75bdaeaf584c3c8040e98cfca01916d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jupyterhub@sha256:6078fb5dcf700ec5588b25b918f53b61022fb98381e09734e759187d220ac378 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jupyterhub@sha256:4aba69867001bf8e78e96052522ae6208e03f8e69888b771ba3699e6e5ca818e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jupyterhub@sha256:a65adf11870ae1b74d73e1471d46b255294dc8356524c8899ca74d644ffbad26 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jupyterhub@sha256:6a81f21927fea679cce1379bdecf8f66d410b9d181ac29ed5a471776ebaa59fc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jupyterhub@sha256:d87c497102dd84241d0fa0c689200c4ab6e0a25b5c279cd7a8f3db472e0c017f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jupyterhub@sha256:101a52e2f0efdd0e8314f012d87cedb3076ada8baedf3a1059081085c827509e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jupyterhub@sha256:e4bb929d84cd1810bdf54f1cd59ef78aa66422667f2342fdf6b1966d0dbd3ca8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jupyterhub@sha256:759457f7ff9902526835fd98255e0bd8e70def9ff22b676e529419cbafb33993 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jupyterhub@sha256:abc0364baeda7d89117ca48702a71dd2d77aebf995dc5d2b0b0a69a28fb1a3df |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jupyterhub@sha256:4e098fb1d934431b8a073036a3bc71c051009c4360f3e384a16f95b69ea96315 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jupyterhub@sha256:98d987c8077c9203e658498513ea66e599eaa0e170fd78bcf45285e02e5762ab |