Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:f63537d5d420c53db9fa6138611ee2362fc5f7a27f27b18d60abcd1376fe72d4

Manifest digest:

sha256:5bf30630304d2c8fbc32e1e72ee75b574bb7815e551b06c436f2a9c2b843b53f

Size

22.63 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8d5a3616284f767c2415349aa47fc8c5df4cf8b40ced05772a7b34433d63c6a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4706f81148ee70ef6e30bc5bec92900023c278ac713021e48d3b2a4efad1c365
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6561aa86b2e936fb2ee0d324faa14c5f651e75d14d1ea082f06b390029b99dd9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:69be8536455d02bf014ea4bf7a4a459e8fffeffe738511aa4d77d13bca150bb5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:b04efa26198f4538b8b765653937acffcb819cb70f10cbb4b0400e4ea5a86f49
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:bb859719a5259359cc2b7b78c38ac1fe2f010a6ce7398f1c39906685e8228e01
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:102adb263cde1947dc7409ec9ccae07fbc01d8c343e1ff900bd5978d8b7a4290
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:362043ac45fe9359ff02c067e0cd1c6ea0e11ef544dfcefba9b7c7cb9bc205e3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6e07fbb4b77f20565737838ae7bb675ed7f972322992d090d054fa54ada65c1d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:24becef875ca0dff2c6d3e92db6c1a48dfcac253d7f4872277a59c802c72204b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bd680a7a274737d498a9c8188f096b285908c6674d4f08e5bb62bc00bdd7e630
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3963fbc0ecac9d7916ceb5b9a4e36739de1c7052eb2f9c4ee1ff9cc2cc4229e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:8ccdcd3d3fd8139038085346f4862c1951e751a7cfd1b15266989d2fe00ef8b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2f7a1909b256f9dfe85023a95d27aa7bb44827b4e5f1d763938c876ebb79a404
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c6f16abd1a1cac4cf7ab83c185a18085d97e855488915c69083270b1cb6f6e0d