Sign inSign up
Supabase Studio

dhi.io/supabase-studio

Supabase Studio 2026.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2026-debian-fips, 2026-debian13-fips, 2026-fips, 2026.09-debian-fips, 2026.09-debian13-fips, 2026.09-fips, 2026.09.07-debian-fips, 2026.09.07-debian13-fips, 2026.09.07-fips

Index digest:

sha256:d1b2c4e2bc2f9dd6be34dc420789d28bed1d5f71acd4466db416e374bb376581

Manifest digest:

sha256:3168cd5201c6c73a25d98af65cc12907a9ea9ae23c5561ef16c9d684f8a94243

Size

93.74 MB

Last pushed

4 hours ago

Vulnerabilities

2
5
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/supabase-studio:2026-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/supabase-studio:2026-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/supabase-studio@sha256:e7e0f4334460404602e02afba9ce9beab38daa19f4d8bb2f1afc941586829abf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/supabase-studio@sha256:81c763de3d46046484af7bf3793aa781918ecdac27ebbbd869e4e1f9dfe6b6d1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/supabase-studio@sha256:40df09d96b0c19c247bf6345e1501af0f476231764804c3be12f998ecfb85f7c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/supabase-studio@sha256:6d5273c60cb70d6d2a768c731edcf53d5db23e1b6a2975439a15d65978b8286e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/supabase-studio@sha256:0a171b01c6fe6d45ad0631c02fd1d48df043702a4c24c29df9d550876ef28e52
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/supabase-studio@sha256:e30e5cbdd0cf714cf24436462c8831eb096d19b4773feead8cfdecf587f2f7a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/supabase-studio@sha256:e2d5abf5cab3d8d25d8fe946fb9a191f3945689d817463e03b8beb78ce8e81d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/supabase-studio@sha256:a2b82d4eee2a639c2f3c447e227b778b7713253ff780b091aa51a494e81414fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/supabase-studio@sha256:c365b305c1674952307e2742f840cacfd3ebf9adaced7334828b1b9672cc45f8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/supabase-studio@sha256:e0803aa1c67383daa1e3d4ec9aeed190ac81fcdeda16decd7db6bd909f71bbad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/supabase-studio@sha256:f3c0c7aba32caa6e5ef0b2f6b5d1c52b84cccfea09d39bc98d530391454c9ead
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/supabase-studio@sha256:2cf3f56bfe01bf48a8d915642df6d7d2c97f3ca852f5616878241c5c3754f6e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/supabase-studio@sha256:671e07a148d46311739448b9b97513ecd85fe732f38c47eb143d918a4f605376
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/supabase-studio@sha256:dac9e3e3c56fe25c774af057592de00d1af5403b7af872ff8f827c15c65f2dc8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/supabase-studio@sha256:774b3856b224e74e9562eb5c4e47eee3376b1db483d49b0a8a363a46cb8e660e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/supabase-studio@sha256:7d58cb31422e0b45be8e7fe08f3134f448dbe5a09787c815c2901677981d81b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/supabase-studio@sha256:842ea66c157ce96613eadf9e3cebbb5631d1bc286689c6a49e5d189e9651bcfb