Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:09fde598e7de8c9b60aa36389998c059c08998dd697705fc1fada8bc4b5caa5f

Manifest digest:

sha256:5da520f4d7c7ae83c853aed0e083fad86dbbd03c05187ff6591684db48b9b8b9

Size

22.63 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:068be03cddef788ededb0a6ac91c22bb72cf334e9d4f933a02ab5f0df53d5b96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a8c19a9c29fe02ab6cbfe48f5ec169754ef796e7d7a6a1f037e00fc6d169b93b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:54f11c09a3e38d6f1dce88cb7caec2d68b69520af4c207df50b338cbc97b152f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:344e245dd9d60eeb51caa5786d79e8510d80a788efee285ad83283c6b0ef2ea2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:80fde16f30e2cf6d75d74477d9c49ba3984f95a3818707264a5670d510b4d72e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:43b1780f5b8e25d4808281295a6d31be8201468f8e99b1b1c58c7fa482a23fe8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:af3083950f197a7d5258ceb264ea6ed2b207e301ebdc79d79167ca5aad6f40ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1006f4d11a1f6a2debd62711c57128e8d34ddd955eefbd31c6868c786210fe46
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6ba10189d46aef344b4a3976154a237472287bc3cf583ce49c9f596e3c1c9e99
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:40f26d232845e3ea6932f4ac7d387c5005a8d5762782052c308b7ccc344f8b32
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:c39689473be5e81394c401c04082cc95d6ba6d0a9763c30d28abafdbb1f9b09c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:813a2cd15618d5c040e89dc1bd194521e68ad4c539b44640de53a28f87324068
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:b38b82221e47105d63c619308925f7d257f9cd236df03617f1ea172f0ea74fe2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:a1a027599d548a428d1e53ae4c0dd54bbceded58de35c325075e8a0b3a019aec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:484571949280e576ebb7c1bb98ee852c3425a17f966efead30ba84010d2f0212