Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.7-alpine3.23-dev

Index digest:

sha256:e18a89c004dc552b205be833363cc0c2e7976d82c75101893b7e56389d51b5ba

Manifest digest:

sha256:3fee1a2977a7c40cd967e184886a72aa29f55e120fe64a967738c955f6591b9c

Size

93.67 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
2
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8b4df7f42f69058e3d6182e94c2befc07617c4179e971778f733c3665f5e5fd6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c1eda45352ea316808c2fb86a18c7112b878d5ecb3da0ef83b6dc3f6c0dedcd4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5a805c39bc3fd5855bb2b9944b7812a14c9ab38561d10e2392b0cbbd3681a61c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:98bb1c242c5ae67e5a381427fbbcff7b31fb62bedf4b5d7500c031019e546979
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4414975cf0f7954349028e028cfddc54a05eda83b9a356213c946386ba00bbc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ba86fae190bca9755f10cdac9b9018faa64446503262b15132aacd08f0c7a6f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8000e1291ce46ed7fdfdf4e2b69e584fcc9541205362682e39548ff9aff9210d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8678a8ab206b5229788ff342864c8a6cd2d4d867b2093bd483a28ce5a38a8416
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1876b1524ac6b06e60709086ed0ccddcfa291f63795df0fe7aafea087191c1f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:198bd27d0e83c64a782903e0cfc0f2eef484f8bee55dd5c5bafefd6479629a3c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:815946561037dabecc0a6e7cb5181bdfefa6835f709a8757877281fd9ac167fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e203562fce542abc37e6ce6e6f615a35eb56740617185c615375165a8e06b9f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:86572d0594bf9f1d501321ff7b9b15556a2580b32598e5a0899599e281311a78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e2725181fe4314e01d3449b67b2d32a5eb454fd369f06da52eb3c60f86fcabe5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:88367a5f7c2efe193dba2e4c562fd9faa0197e6d916c5ed0915fb7932105e632