Sign inSign up
Supabase Studio

dhi.io/supabase-studio

Supabase Studio 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.09, 2026.09-debian, 2026.09-debian13, 2026.09.07, 2026.09.07-debian, 2026.09.07-debian13

Index digest:

sha256:e2852fad3968e56d1c1417f9f813480cea8cc3ccc65b5c7aba7db166b1ed401d

Manifest digest:

sha256:58b507dd2faf732a3f42d4fdc0680ca806e1c4e9a349bc0d35800d72078d1c21

Size

92.95 MB

Last pushed

58 minutes ago

Vulnerabilities

2
5
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/supabase-studio:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/supabase-studio:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/supabase-studio@sha256:a8284d56ad9857972c9bfbe87b843d900167fd8f67ac4ea528fa026b9ed46867
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/supabase-studio@sha256:543e3ae6ab4b4edb5c9ff6e9f1fd12c4e741554d73c746a966028d8e79470cce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/supabase-studio@sha256:07fc20de9795651bc3d746f0d89c76e4fba6c77f9800a973d38c026da5fabf99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/supabase-studio@sha256:94aa60f75c3da3b47e3459f4b7b26bd03ffaf31f1a57eac3d9c59e07df1a0754
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/supabase-studio@sha256:3ab5a15ac8bce88a0183beb2c34cdbb3307e9b490baf7518eabc81185610deb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/supabase-studio@sha256:af5366ff3aaedaa1f6dfff30a7585106e4cb185edc9e7249459a7c689de338ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/supabase-studio@sha256:4f3072ba2b9cc48f0ec57111412500646adc4813b6042c52a33074032ca48cb7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/supabase-studio@sha256:d346e2566e002d8e7796f46a2df1fe305d09da1df54fb0bfb445df3c3c63bd04
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/supabase-studio@sha256:d023c3169b993f2774a7665035a2c194bcd5ffe3e2dd2659b7b647dc1b9e9dfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/supabase-studio@sha256:fc224323ed261947016553d77df1c58251131428b50783b0b02bed24991fd6f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/supabase-studio@sha256:99823f406a0840e4c3c0faec4f09fe0fe82ff97b5ebfb4ddf941a9f5369525f9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/supabase-studio@sha256:c6a56562a1c9d7eed6e56fe684e30eabf528189431e35f746f209761f510c034
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/supabase-studio@sha256:fa4abae787dab472a11a34063dbdd2f141deaaf8427400c44ad188804cf61dbc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/supabase-studio@sha256:97c9c62f0a4b5b3295c9e4dfbcd6e04b5cc3c77545bedb84fa86819bdc4e472a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/supabase-studio@sha256:ad3a909d3beeebaaf42c552cb1d8c12fbc27be95ee03e2d2b365c730fca1b653