Sign inSign up
Supabase Studio

dhi.io/supabase-studio

Supabase Studio 2026.x (dev)

CIS
linux/amd64
debian 13
Tags:

2026-debian-dev, 2026-debian13-dev, 2026-dev, 2026.09-debian-dev, 2026.09-debian13-dev, 2026.09-dev, 2026.09.07-debian-dev, 2026.09.07-debian13-dev, 2026.09.07-dev

Index digest:

sha256:89da609b17c878dae7c0e7bc3bbb81a17163f9f441af9ae7e9d33057f78360f6

Manifest digest:

sha256:13845592878286d3bc54f6498939961505480b09be1578127cb21c7d7a801525

Size

107.04 MB

Last pushed

1 hour ago

Vulnerabilities

2
5
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/supabase-studio:2026-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/supabase-studio:2026-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/supabase-studio@sha256:22187df6f3e183dd5dcb230133a5d4c59415b418ea9566e09ccb6d122269ad68
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/supabase-studio@sha256:7e431f2d81e67923c8b17700e9d83b398ee572b557d8efc0c00865a27f3a8699
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/supabase-studio@sha256:68e4d54d343e2187fbb8a65a0dd60cc4d3d1f668db138559a2c32e9fa204e2c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/supabase-studio@sha256:6c57ec667b6755fe9420d651f3be517d3583622feb4b2b57e0d922cd97869355
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/supabase-studio@sha256:251c366ca3dd52de92731b3bca4fc6b39c77fa0a562031ed39f0e97c61bb5c6f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/supabase-studio@sha256:772a290e9710c5b73ceddc6e57daef0fc3143f3c641bf42b7bcc207f9ea94549
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/supabase-studio@sha256:7d9064bb9deff4d0c33cdfad26977aeedfdae83b0e41e8dffbe30e63cf25b8c9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/supabase-studio@sha256:c75157f145e4777617846db49a4c5ddc801607f552bafd2348d6e7208747e730
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/supabase-studio@sha256:66a0ea6477f068354cbdf023c02499cbe4fec4cc16db437be238cca8c8ab3a69
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/supabase-studio@sha256:ee424819f161720b565a1faf63450c63bae682f5b08f2d57bb932826f695124f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/supabase-studio@sha256:6ca1860591be76d308b6f5d8d0da2cdd5cd211865673ee880f2a93bbd1e0a5de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/supabase-studio@sha256:34724b024280f7711a8587112333de0a08ca1a464942eee310b3f3edad00ad4e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/supabase-studio@sha256:e229a44e7b18ea9fa206b90f32b774ece6ac23d298348b718812331821290265
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/supabase-studio@sha256:1d3904aa54d0e0c54feb8e3fd42de11cdde79dad2202db02a2a23752b447075a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/supabase-studio@sha256:3de9ccd6f894ea69d9d02423e43c1e3692c8f998e53dda0be0196d99f695a91d