dhi.io/ruby
4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.6-debian-dev, 4.0.6-debian13-dev, 4.0.6-dev
sha256:b13643af2993348019661e58627225b4f4584a5d6524603ef8fff13f638898fe
Manifest digest:sha256:5cf0784ff58f4f427e4237dc91a8524b756e3f70c5b587a9be2dfb5df9f2c922
Size
136.66 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:65bbbf88020c14f9c0ec344da0b19841c4373e2142010fb840c492c79dc3c681 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:0d71930e7267664101ed8cac61ed021f9d64b3a78ad3b2a67fbca440b5f23d18 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:dec6629604927067a4e60bc16ecbca4d3e3462485f56022e68cb8d6e9a4c0a62 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:426513e5cef108bd15e0669f6ea7b7b9682710986d61cbfbfb138e064f63f603 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:5bff1bec6f90e0eada6435c155a978584376687963e0e7aced267b7da26808ac |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:8527db99a218be8d3fe7e3b148142fd2d09d0ad9cd9744b83d716058ec562900 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:498e73b7c7efd6b49d34c482a90c6ecd5483de9fadc2b41d28794b4f49e125b6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:9134c25532d40d7951888b942d1cdba816f20c6f9966693763a15c61a37d46a0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:ce9073d6141db8793f1b6b441b394975698b12397c1ee64ef925c71609b34df1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:3126ce21d866dc3a5a6b998303a197b4d80fac0b824fbd9103a15c59f34a11a3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:b62c98804308fb6ea9bae37787a39f8c119cab15cc4503bcab997adc5f7bc95e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:41183db866bc003bb1913b07b8c93e7bec48c86393b6004d12f58ce3b12e61ef |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:ebb864f19fe38d9dc175a219860fe0b50b4ace4551aaa817a6b1a62c04c3a7ae |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:273f9fc21779944286689909a59369b7f58d4bc0992e8d0bf5d3cb491b819c70 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:afce39265dcc6b1f75a7843bb61f66c5dece2f05e16c46874cbc09933670166b |