dhi.io/ruby
4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.6-debian-dev, 4.0.6-debian13-dev, 4.0.6-dev
sha256:dc24546e53aa141f9eb833c32ce595e4fd9fb234586ff43e7e79856d0b2ae1eb
Manifest digest:sha256:c6b972a0afb1353ccf754e0cdc4d7bc3563c465562b5e62855bdae614e68f67b
Size
136.66 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:0f4d9b8a72f46999ec232e4451884ec312077022cb1ebe5ca2a88e1bafe41cc4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:5c4c3de9ded03384fc00bcd6b7c8a13b0816b87afd32d92592f586ff41caa21b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:b4f8436dd4eb025388b4299186f41ffda41791f5930c18a0ad76bfac3226239c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:f3fddfa73cb872f55821ede37775c8b39e34a5bdf2d76a2d9f4b734b3ac3d64c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:c7ae8ae80de904c51777ac1521c11350c5198c9378c4da3d3de80a7435ed8bb7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:9d57ca266efc0ef237df9f246cc2c9b33a66335f8bdb48d63514235d82afda21 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:cd80441212395011d2ad53896412b86c47b96bc8c6251a561802170e18e82e65 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:fcc6fffba5e05cf89530e0c65fb94c0272a05a4d3c731a1863d1598bf01c1711 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:5fdcbb893f0a807960981d26ed835432c3bf370bc044dc8bb85d790e588fa217 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:fd2097c31e4ee6fbcea26049831ef3d2d8b0327c66947c442e3724c40c180561 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:749ce67662eb18f16600d5a35f4d470a5f49206f551f8e7e1210496d70784014 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:bab929ec06326c2432f69161c0a4f5ff259e838da5d76c823c67c99609b8f0eb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:5043897490b2b7107c316111fc45ebc478bff0dfdf573d200ea6c1877b17ebfe |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:6bf5320fef84cea0b8ae0ce9101ae2f480163742cd1b4b3ca46fdc267d7c9967 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:934b2f78a127290c716686e4012abb658e5e0583f37318d7d4755f62442bd86b |