Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.7-alpine3.23-dev

Index digest:

sha256:31699abe44f95f19744ded2900604d7e9f10e6f532e2538f08244bfdac76d1f8

Manifest digest:

sha256:199b4f7993e3128342640b3a1fbcc209bdbdc006bf8c64b592dc518620d2fda1

Size

93.68 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:832fb0a719c4abd03ae769870a8ded5e9dcabe6062419fe985ec62bc1261a2ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:686385e461a1b814b285d3745c05ac6dfc0d1f813bfaa671449fa3b2f526bb3c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:9871cdac5a04e074e9868b6c07619e723c79267b4b79d7f7a4292376bf870693
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:65774746b9061c06f73ef5b3228fbb35360e8404fe07e76edc327ba37c865ca1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f493d8214bd6d67d301742065f0ffbdfa7670ef5bef505f9badff17f4054c6d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7eeb3ab90d29a145b87d1a6b12de9f9e3d8051d2ed19e6d0241ca1a0b56b2ec6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1db942b7e362c3c8375f46e9222ee3d6f257cc8d83c1ea99bb0597af3dc25ff7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e289c934113efb618734705c8ebf103353f36c8eac28c6dfbc4744e96b650ffc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:bc03833c2eea2da9232fa5ae9df3369d2608a89f54132c9569925d31ae794d3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:940b1106c24649ad225962e9ad78319a1d4f66dda609f024da3f8b233c9b8896
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ae9949490244f7ef8016a3511de3ff8547d4a7e3d30416d92acc442a9f4d1f0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:86dfc79fb7811fc66a8db458c62f793d3d602ce44ed2f70e673facab5452661a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:edc78f85660ac915ce193235cf374d4248d595a4e4e94cc668126464c27ca6ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:11771a0facad7b2b51066a48ba9eceff4dc956e022a56dad90a7aa7c527e94fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:43396be1d512488409aa7860a4ff4a969b55d7fcac5311b3b06db87a2de2b384