Sign inSign up
JRuby

dhi.io/jruby

JRuby 9.x (dev)

CIS
linux/amd64
debian 13
Tags:

9-debian-dev, 9-debian13-dev, 9-dev, 9.4-debian-dev, 9.4-debian13-dev, 9.4-dev, 9.4.15-debian-dev, 9.4.15-debian13-dev, 9.4.15-dev

Index digest:

sha256:dc270618924dd26c93e2ec2a221a606171c725b4d5b93bb2163e65d3bce41549

Manifest digest:

sha256:8c92910198f048d5e37e5f9a57cfaa601325ab4f39faf20a83bc8cf92d26c992

Size

343.95 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jruby:9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jruby:9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jruby@sha256:4c2e96a843de5437504e5ea077dc6f97e819ae82cf2c447d0c36c5e96ca1dc35
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jruby@sha256:3bd88561246ffc4020bedecd1f1481468a687ae0c5aa470ac86d3d3a7591e585
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jruby@sha256:90c79b286eba1048be64d73b81d82d62411ed7d98e3439a047159154b7a8569c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jruby@sha256:ac7bb65a9b281e356838459c8738b36a2bac1fc28a0957ee7a992cb659d3f85d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jruby@sha256:9293c8f1d5d1ed6b05a145158b2dcd09a94a47ad39c2e3b6026bcca948a38bb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jruby@sha256:1d394b0d2b14899481a6500e38266211b85b225696a0368e22635f99468f29cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jruby@sha256:1bb3c3745e361f868cb12477b11d1e455f96c46bc5d072d5ee052c336dc0f524
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jruby@sha256:6d5ab6f653d2635bbb09dde9fee85754c98ec9384415e7d92d86c3e6e9283063
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jruby@sha256:a7112cc27cb794ed838a161f39a2f84aade09fe74d6d1ea1220a443b0615b6ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jruby@sha256:dd70f92243d4150584875247d63c240840b5d389b934de6faae39dadec30a528
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jruby@sha256:b80611a805de862326e6d82f3bdbd807cf474d7107610070acadd5f947208107
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jruby@sha256:7b39cd2d98abf2c6e3428465c56337f96fdb7ef46b25ea1174888dac7823407b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jruby@sha256:1c9159e9656970c113e0032363f76cc2aedc2e267a0ce0d47a0ae405ee701e85
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jruby@sha256:59c4649c5ed96bf80247d1b38a89b22fa6c2de6aadd481150ab82458ba16914c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jruby@sha256:70cb8eb13e8f6cd51626a79df0ac64707c9212ff8f0bcad8cee0083c7455a773