Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.7-debian-dev, 4.0.7-debian13-dev, 4.0.7-dev

Index digest:

sha256:24dba7b8ea3f36c14c94c39cc1d8f6081439efdbb3547e0e00e12b4bfc1fde93

Manifest digest:

sha256:97c1e79d5259d64360bc5403bdb88dd548790020146cb245e1ef2cbc90c34301

Size

136.66 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ab18ab06f01b2a9e9a211ef1a91e253d09420d5353efec3e303d3671e10826e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:946fd3c4c931f33fde4eb70dd0c04b8315ef927e1b699c9833c48d61cb77a9e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:77dd3c6c8e793451e803fba8de21608d8716e493dfec0ec91fcbcc8cee85e4c5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:27a3ff018c84f0c59a7feabe5707af03f7661ae41e4927b833f9bb6e0fb05631
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5a7deb9a4e858a887de5d33a45090753e5bcd1ba35e68ffdb8af999f26c9fc98
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b734a13df7522dfe859a992caa01f09edb5b6ea9f9c10567a4de5375df3d7130
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:c3dd1f9bf7768ffc069a65a2f91df39ec98f67ee5940a80bdcfbbbbc6149c04f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:310cecbe3fadee088e77cd8368fd4206b0a7139c256ec8c6f73828ac51d43e07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:54bfb741cfe2b9c917c0b9fdadff7150e89b9ea40891a50d4a246a16b4544942
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a8c213e75b6ac8a6daf707f563adca3d517787fea09982c09185264e5e73d59e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b4ac17de807291d1d4eae725e5a7dbe490993392f89472ce2ac44b34024ac71e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:454d1ea43283b508ace3bb3f80ee08c3a3c2b8ad86abc4a9a2a30fab6cc74a91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:168748af89339a26dbabe0950320a00e6c42a6e120fb8fd245d9ae585858ecae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:95c486bc8d1f5e247a5dfe86255c66a3366f8e53ddb23086534b009499c899ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9c729f7ee4de65a2479e3256b819fbd12f7da14e041ec438f94090ffe653b1c7