Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.6-debian-dev, 4.0.6-debian13-dev, 4.0.6-dev

Index digest:

sha256:b13643af2993348019661e58627225b4f4584a5d6524603ef8fff13f638898fe

Manifest digest:

sha256:5cf0784ff58f4f427e4237dc91a8524b756e3f70c5b587a9be2dfb5df9f2c922

Size

136.66 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:65bbbf88020c14f9c0ec344da0b19841c4373e2142010fb840c492c79dc3c681
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0d71930e7267664101ed8cac61ed021f9d64b3a78ad3b2a67fbca440b5f23d18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:dec6629604927067a4e60bc16ecbca4d3e3462485f56022e68cb8d6e9a4c0a62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:426513e5cef108bd15e0669f6ea7b7b9682710986d61cbfbfb138e064f63f603
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5bff1bec6f90e0eada6435c155a978584376687963e0e7aced267b7da26808ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8527db99a218be8d3fe7e3b148142fd2d09d0ad9cd9744b83d716058ec562900
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:498e73b7c7efd6b49d34c482a90c6ecd5483de9fadc2b41d28794b4f49e125b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9134c25532d40d7951888b942d1cdba816f20c6f9966693763a15c61a37d46a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ce9073d6141db8793f1b6b441b394975698b12397c1ee64ef925c71609b34df1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3126ce21d866dc3a5a6b998303a197b4d80fac0b824fbd9103a15c59f34a11a3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b62c98804308fb6ea9bae37787a39f8c119cab15cc4503bcab997adc5f7bc95e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:41183db866bc003bb1913b07b8c93e7bec48c86393b6004d12f58ce3b12e61ef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ebb864f19fe38d9dc175a219860fe0b50b4ace4551aaa817a6b1a62c04c3a7ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:273f9fc21779944286689909a59369b7f58d4bc0992e8d0bf5d3cb491b819c70
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:afce39265dcc6b1f75a7843bb61f66c5dece2f05e16c46874cbc09933670166b