dhi.io/jupyterhub
5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.5-debian-fips-dev, 5.5-debian13-fips-dev, 5.5-fips-dev, 5.5.2-debian-fips-dev, 5.5.2-debian13-fips-dev, 5.5.2-fips-dev
sha256:0030e81e664aae203af4409a2047d955e2168b9d554c48d1634d67410c266c55
Manifest digest:sha256:d17c5756ffe5239ee6f7a7548fdea0802b3a235e7f1c6e442dde85e1ff08499a
Size
85.87 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jupyterhub:5-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jupyterhub:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jupyterhub@sha256:c08f8daa9b2cd8f61325e8a83804b916b0481c121b7308c0471f3c15affe3e45 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jupyterhub@sha256:781fa2b93157f352dec0f86082867dbd9cb36a40873acb9ecded3c3a939e0b9d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/jupyterhub@sha256:ade851491eb29a7afbd884d3d065bc9c28cce015a569f50a9ecc171c39c76ea7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jupyterhub@sha256:24cdb9813727cb61e8e731b6327188f39cc9c866288515db92bb95aa15f84e80 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/jupyterhub@sha256:7b6f0352a65141ce5e58176e4d7f2fa406aa0f040f117795561299881efd9e4a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jupyterhub@sha256:1a274c1e7f4475da0584778669dd004b0a61f2558fee4af716b40c5a32707418 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jupyterhub@sha256:a1b5b153bde42a6bcb3eddc68539d44c052fa7e78354a21a566f1c8c7b0e8430 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jupyterhub@sha256:679da6b48a15786d9200d4677772d57686b121a2fc4893a4a9602b60f285ea76 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jupyterhub@sha256:8c3e863883584ac4281ffcebcd3adc0caf0ca18b817f5ccf5c386cc7b8ad0a0d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jupyterhub@sha256:e6f1c42afec2a7852fd4e80e2a5b87701dbf10d6af0ec477bc5d64bc3a091f36 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jupyterhub@sha256:770521e8431c467657c4a3c19e7eda4478c3d3782b0f34d800fe254dd0dd6334 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jupyterhub@sha256:66d04f2faa29b5171178b2f2e57739abdd2fe12985edf3bbcee321a29abba0f7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jupyterhub@sha256:f994a1b2f150da1e22531e8f3a66180ef3924fd44c35c2c54b0dfd54e7f3379e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jupyterhub@sha256:874674661ebfb80f38f64faa365a61041e04e52b34ab81a73548f9c2a3a40ce7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jupyterhub@sha256:d105b737f4c345dccbf4630a1e6e816bc1d3c07ad949c526f246d7b5f53fd2b0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jupyterhub@sha256:d8eb50db4fd5f6666bbe943b2c7c657e0ce45a040b591a4862e5bc4150b0a5f5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jupyterhub@sha256:d289474e7a058c373849f41a44738b4a1a521cc276c2f7e4c7e42d270413ef7a |