Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/arm64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:8c384a0147e333c96b5b65ba76401bf5adac2138f44b497646daa72ccc890a0d

Manifest digest:

sha256:780f999cd38ecb17f777e0c9ff73b4e96e62e6396c5652405c0513f6ecc35d77

Size

22.35 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:6455cda09a1dda02221c59a25f2c3b540f246cc9be5ee7aed4c8e71cd9652f00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:442f2041928039a60077bce6498f88a7dd18c58183daf7d22c87bf1676e4f355
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3259b36013e74b3a5b1f115e4799a6bdee99f9e12124da2fd19d0e141a151f32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1a8a2031b940febda09490d21243c2682edb0b30ea173edd24cdba64954d508c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:1e8adee4ad541b3bb7b2ab39d1fed624f1d4aae3b1460502e7dc0e7051a85442
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:bf891fe4f481907b969782a8fedb24a8d41edad0ce844b480346140af0ad1064
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d04db67c59ba70c0521574aa0f353784febd3bf15ff720ae3b277dcfdf2916e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:0afff70131fe99ed04cd83e9e4781eea619ca06beda8da99bd9dcb294b7bbd0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:692475f284f46ebb6b27c7b519fe66ea96d7348922c55658d2f3a8be265b7cdd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d552e3719d68a9f77869e3327947b20d7684963d52c73155d34db8ecece8ea57
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:3b8f0c96f0a065c5f93bfcf4db02456cca4bd93023c66b0ad175faacdf94fd41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:09a91db4ff01ef81bbd0bcac937b750dfebccada2d2cb4d83909894ddb500387
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:18704bed13623be299991f2ff9c2c68c4bc8fb21d3677c31b28131d6dd2cb0a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:8e152653f7d2be37bb77e87c669f4c524955aa4be8b45efe7fa6781f70082c64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f2d4f7a263ae56cae9db7630441b4d1872b5274efcbe8cc5b41fa63378cfd51b