dhi.io/ruby
4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13
sha256:b09912a1ccef7e919a3efa3604c9293117149d3740a5bcbae935dac7ebe3b1cb
Manifest digest:sha256:7e7ed85d468361689d7eab52aaf24467a98a4ff24a9a74942309144d34139c2f
Size
22.63 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:1b19d6c3f4409ee8a30022fca826ad6653570e7aa922f842f8f5137778d23011 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:22958785e027536954239db14c33d89e21475b1a268e4322668903083cb0b147 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:7f33a6a7ea9054b30684266fe6fbeacd781b0f4a22d74c57819f0d084128ad78 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:76a3d641e26c5b08cded5dcc062d8274e714e4fba1eda581def214751f830c56 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:d01b15edc027fa315fcf6573d0f06c19442f7cf4a86879c94488e141e9fd0538 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:ea5597dae0ddedec728cd64abcf7c8f617a0875af5913d6113d735a56172960e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:a25742fd90d663e4b4bc73ac2c4c26a2051e09d0539e3ff39e0ef22f859bb64d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:a57b14ecfa4e33199a175ed309e48dcd1b0ec7681f792427c609b318ef1aa621 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:4d4c5f00c3d91365039cc667cbce9da0030a0c946a4d0fb93e6089c3bf097a4b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:1417f1ddf7d1dead28f6615806e3bdaa0be4a2b3bf43ae8149771c5d13cb46ec |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:95be92ff668e912b37021240d125c9db1293899d7fa0607e02c8ee89e713f1a5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:61a19f3dd6db97532c83894b4df7b90042d485464be92ede8af5ae1077f28a27 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:38b6240530843ec0362acc303f7c1744995d57da3fde5bbd977630926f518a83 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:7828e2416f72f711279dd46015d7be508102d8e0120721977f7f7a1f39b9c2e0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:bd4edb46bd8e3351aeb37618f37afe053f4dca2f0bbff7b46eace00ad6069cb1 |