Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.0-alpine-dev, 4.0-alpine3.24-dev, 4.0.7-alpine-dev, 4.0.7-alpine3.24-dev

Index digest:

sha256:1a326f9a991938f23537cea3ccb7d34145becda238dc0bc5b9d8e1635d94a6b8

Manifest digest:

sha256:bd73e28ffc7181cf71742c96da73b41db5f637762489143c48d35486ae59e4a0

Size

93.73 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:9084cc719b77f4e1832d6d7a86149bed9cee441c365f3d799500b4154afbb2c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d7044b6496a356a61192dadd524385cc0ff54b520ea549c5df4242ddac416797
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:e3054c73ba824d60cb16853090f1a44ca77193b22cd2954cd2416393787bfb88
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6b2cdefac54266af04ca3900f24fc1db56c4e8502c665f9628a9528a17483a7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:70f153b7d6d8414b9eec34cfd37cafd0560572ce16c4bf6cc1fc9852beec628a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4b7deb473f1f368e14ea1a2579b414ceb5a6ee1545493f15c85c56fde3726294
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:68ebe794100631595059560e179bae3d4405795b747bbf8a8961c6b04c33e5c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:30ea696711516d0d72bba80d9ea538eced89917bfe1fbec362c3a699ccf5a4be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f435bce3bcff848afd577c796b18e2016d9ec83f1eec8e401e9c486ae0ae8704
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:36f05707f1426a11dbe52c4cd81e553de302d462892e6f26aa6af3a747eceb7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:dd0b05e1d34b37f2f9813187d529b2a83f113f7820cfe52ee41c9961d3e01b41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0bbcf03cf094a089a075915c5e95d48cebf56ce4946890de0b8626a350d677b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7bd9e9b201d2d679616a8abc683b35531aad3052af39022ef1a574fe141b707a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:1ae5dbeb42494f7376b8f1458b256e3d7853069d10a25a61d553dbe074b69601
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b8f3aa795e4fed0680e09663b0392f7e1cdf79c4be9f66e0018ac2de8d1c3ef9