Sign inSign up
JupyterHub

dhi.io/jupyterhub

JupyterHub 5.5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.5, 5.5-debian, 5.5-debian13, 5.5.2, 5.5.2-debian, 5.5.2-debian13

Index digest:

sha256:ff6b24536fea6c7333f85ef094175433b8508412e304695c935850f11e5a3f1f

Manifest digest:

sha256:e55ea5f50693df5af8dcd38044606b2cf1809e7a48db5218406666e0ec1e38a2

Size

72.59 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jupyterhub:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jupyterhub:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jupyterhub@sha256:742a83cab49e69cff2e3d5bbb2cbdd2e830950610c3fdb917983b05a186296ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jupyterhub@sha256:de9e6ff954817ae90ed7707317d149078e9599fa68bf44560952878fe7ef4cd2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jupyterhub@sha256:49eac109aebb7743b27f24ef77d563b091c7e3371443bf8f78e78142017bb1a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jupyterhub@sha256:fd25376d875eeddba8c9e1044f3cf12956b14f4391de450c8dc8df3b3d70786c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jupyterhub@sha256:2c4dddcd5a35356f81d2c5290e3c8ef9132fffada11745e814bec84b3f890350
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jupyterhub@sha256:869be92fcc2e6801804ac40dac9d884556e426b7e6e629d00744cc644dea1ae2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jupyterhub@sha256:5ed986e29c93d919999b31511612deff2624f8262fe4f03c405764cbfbfb5b35
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jupyterhub@sha256:ae888ed73718221eced6585aacb01a4d21e21ed19597fb3a84b2d393c43b3666
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jupyterhub@sha256:823ad33ca0b5de2259cc01acf0c5faac99294d90008e0a68be2bce04fa059320
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jupyterhub@sha256:0348a2ed99e4282bb198cb6e2c89ebccb2914516893d45b4d82dc8166398bb33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jupyterhub@sha256:55c5d7a006891bbe94d809db48033436a15d42d09be1ca19f64a8b3e3caec4f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jupyterhub@sha256:4a0e02307a8ff564901cc02a850cc475f3742378c5f5a7c13fa4210cbf9f00a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jupyterhub@sha256:58938f938455a54955d18d962c24cdf63e24e7f002530b97198748dd30e43e9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jupyterhub@sha256:e9d1b4fb49ed0ad87809a6651d75c0caa1d743d125836ccb9b5595f801b7cdfa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jupyterhub@sha256:7a0a5fd2ce333b5994d384b34a9a9ead7037a09c306e9653bfd0336cd7ab53ce