Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:b09912a1ccef7e919a3efa3604c9293117149d3740a5bcbae935dac7ebe3b1cb

Manifest digest:

sha256:7e7ed85d468361689d7eab52aaf24467a98a4ff24a9a74942309144d34139c2f

Size

22.63 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1b19d6c3f4409ee8a30022fca826ad6653570e7aa922f842f8f5137778d23011
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:22958785e027536954239db14c33d89e21475b1a268e4322668903083cb0b147
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7f33a6a7ea9054b30684266fe6fbeacd781b0f4a22d74c57819f0d084128ad78
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:76a3d641e26c5b08cded5dcc062d8274e714e4fba1eda581def214751f830c56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d01b15edc027fa315fcf6573d0f06c19442f7cf4a86879c94488e141e9fd0538
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ea5597dae0ddedec728cd64abcf7c8f617a0875af5913d6113d735a56172960e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a25742fd90d663e4b4bc73ac2c4c26a2051e09d0539e3ff39e0ef22f859bb64d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a57b14ecfa4e33199a175ed309e48dcd1b0ec7681f792427c609b318ef1aa621
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4d4c5f00c3d91365039cc667cbce9da0030a0c946a4d0fb93e6089c3bf097a4b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1417f1ddf7d1dead28f6615806e3bdaa0be4a2b3bf43ae8149771c5d13cb46ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:95be92ff668e912b37021240d125c9db1293899d7fa0607e02c8ee89e713f1a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:61a19f3dd6db97532c83894b4df7b90042d485464be92ede8af5ae1077f28a27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:38b6240530843ec0362acc303f7c1744995d57da3fde5bbd977630926f518a83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7828e2416f72f711279dd46015d7be508102d8e0120721977f7f7a1f39b9c2e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:bd4edb46bd8e3351aeb37618f37afe053f4dca2f0bbff7b46eace00ad6069cb1