Sign inSign up
Supabase Studio

dhi.io/supabase-studio

Supabase Studio 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.09, 2026.09-debian, 2026.09-debian13, 2026.09.07, 2026.09.07-debian, 2026.09.07-debian13

Index digest:

sha256:2daaca52a13fbef3ab91d1d9ace8551883acfdaee2aa280b4bf267bcb1a98efb

Manifest digest:

sha256:f77ec50ed797f4e5b04bb29b187d597870477e714bd38bac8882ccd5486d174e

Size

90.83 MB

Last pushed

24 hours ago

Vulnerabilities

1
2
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/supabase-studio:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/supabase-studio:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/supabase-studio@sha256:cd0f5ca052b4fc268996931486d6805d28d26d7ea67eedebbf155e3f1a45a2f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/supabase-studio@sha256:e91ae0c08448c99d48f61f96f81dbdb2c171cd858e41fbde37a046951968be69
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/supabase-studio@sha256:36880636eb4ed6e3ab286f581dafac1a246fda2499b3b5115b3907a3b85cc0bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/supabase-studio@sha256:5b29d636190d0559e2de9a1f718670ec0b33c2aaddce0594d9073d698ca0abc9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/supabase-studio@sha256:0024d4a1e0115227a14547dc2807861a4fe31050115f772b4c230e9f94836e64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/supabase-studio@sha256:d68b0f2af2ac7d84b92f9032de5ca35220873e96a939deb93f2f967193ce6161
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/supabase-studio@sha256:914a9312249962b8926eac9873c4d618bd59f324bea44e22b2e186aa48468be6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/supabase-studio@sha256:a386441e3973e9e99bad11f028d83cb835aa6dac69c886bd60f5d0f3bcdebc98
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/supabase-studio@sha256:7b430d4aab3a81a53f972485bb474815b430261cdc739483b67533aec3bb1bd4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/supabase-studio@sha256:0943ae38bda7c6c269d066dc7760a8e2e28d967f26e5ffe836ca3b74f7fd1e56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/supabase-studio@sha256:a87f39408199ca752a7718993e87e11f2b045ca7408ac683ea2b9d5fb4b11d31
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/supabase-studio@sha256:3c51fc02a3b96aa93fa79f7aff91957488f751c4e353329f5e2107d3b9fabd4b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/supabase-studio@sha256:4c6d2e0ce83eb2fe65a29092e9f19fa31dd7932aa7fc730cb3cd58893d470941
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/supabase-studio@sha256:95885cb441744017123c375f0b098367c1dc4a74c77ff3cfa0473c8c1b14e0f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/supabase-studio@sha256:aa522b24aaa220e157bee6d2eb8d5f187916ab59e78e71ebdef1307e971a57db