Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:acae19744e30d18f5cb0ecbe751d52db3aae7c3b3be2d898264040b23cb7f2fe

Manifest digest:

sha256:223c6cfb5d4c168c8124fb0029457b517e3de203d0ecac803bf8479ce914e98d

Size

22.63 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0da3deed1d3c33de7a8221bf0f0eb07f6b3cffc8dc8df7860962467b76c5413d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:53a7ff56261ca474bf483d7406fc784c128232cdb15c1d955e756b27490ab7b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:34b88e36513670d90827a5980a708a7a07e0cbe3d2e668c07429d27f11789a98
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b4d65d3255dd5c227e56b3851ce28b1057256a4b1a895dbdda35c0fb58b6db7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:49d52c3cd4e1e578f3cd5f91cdd3ce1c2589a59a5c96376cbb6d4b6a4a1a1b07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:40dd37aa8f8a34a481a6e66f73a32b07a319d180460abee4a54827c4e246e0cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3ae06cc288180c49aab73a05718dacde2b9e9d1ab81f406171ac3ccb8a69d532
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9b98f3e2149fec9a501af19841c5722ff58356b53d3fdcd1ff883a036c137be4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:41af0cedc719ffd14a20118c21173505a1c4148d7a87e2d844a975b2fe8c6964
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:449664877ab197c663b5d0e3c734499bee1a4f372bd0762ca4411dd013db9bbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6a04082ed3977abbc6b871e289ef3a48823d3dae1db528dff5e0bbd5f454bdf9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0a47c382e7d7d98c4001dca6e905d17fbc0e9c85621b45d76c077b52206f24ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1c524ed19e951ba56cb8303448b7afba275c77f1679f31a293889206cba7867e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:fd3a0d1dd5fc5103ed47131bd1ca1041760a6d32af6b9b16925cb5779bda6158
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9ca7ee5f07d6570a35664a6e7ed50371b4ae17ea59d3e85c75b82667b4401c6b