Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13

Index digest:

sha256:8c384a0147e333c96b5b65ba76401bf5adac2138f44b497646daa72ccc890a0d

Manifest digest:

sha256:edd84d25bde97bc8a80ef5efb372c90071aaad9866721f90062ec3b2eefec769

Size

22.63 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3ecef9c8e42c30c2b6632975b2010af5b31b1b189308f36fd84eea3bfc720dfd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8ef812cf64d80e320560512ce0a90275bc6c2a517f9da5c1722fe5ad4faa4a01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0d11179edb69556ee7a3f15572c91713302b25fcf045d8d4a65aedb8e934f175
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d9e5817357879330f2f3928a092cda2dac877e31d7165e07c863e738ae699d5e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:61c7b278b4102a37669185fdb4a3a54442c9d3fa3f6e4607424cbb029ded83c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:742a8e70736bd3051b4ca52ab785c560accbce81d11c2c5fbdcf59d798a4bd04
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ada6a3041174c70c6bebdab94cc90e701600a0fcd8c8c978767ff7ecba33eec6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:78774614c1cf7d8e32c0eb9a60ae5f1f8dbf155faedb0929c8c6af5b17660be4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f8e21926d403b6a8354e5890506d59d61ede8ed5029c6185e09b4f328e832d07
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:28fdaf74592452fd259e77bf57d0efcaf5848035717516912b7a6893f3c8aa58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b3d68d1ee752ff11f038c88fc0f74ba10f7904034ee3554774db8dff16822351
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0f06df4261c2879429805549709372e565e0b6861d7a6ad2d457da036b0b0a0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:be765774ac0663c0e54736ebd982a840ed2ec1ae16e257eab79a44015540b44d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f9f1b6ba85f09337b31324947a124a408de201cfff81dd5ed71f1015d3540aaf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:1df7fc2f90a7a41e4a9291df3979f3b3998f6edbfe9a272055046376d82ec691