dhi.io/ruby
4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.7, 4.0.7-debian, 4.0.7-debian13
sha256:44bf399a0da6ebaa9c7e078ffeaab16b25146aafd90712a92bd37a3bca3302af
Manifest digest:sha256:feff33845f0eb020ae87276c835164f4c177dd2bb1c99352ae78491eadf946da
Size
22.63 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:9b2a9f149a56c43296d1824fbd44d90af42c28dfaee03911727d67f0bffc126a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:e56b5beb8bf63f36bb71abb0359fbfad622af5753d8fdab4fe3aa987063636cb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:3df761c379bbf626e3767fe370b32e2d47ed0b4f92d5cc680cf1112aa13e9cf6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:06413175b0512352ae84d0b12adddf9d16e4b8b510c9bc5a66a498c046fa4282 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:7174dc7c6a3cfe9b6dbc135ba1e55606fe2037be20cd017c1b9f3992bc1695c1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:05b3c0710ffd2e02632289e121a7f972cb42c83a55118499f91be63a476f653d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:736003fdb71bc3637913f6aadc5ef7cb1ddcdddaa061e1f1613eed1c49e6f2c0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:6e5e0f8ca3474d6389f1063cbfb12f2b3f405eaef2a502977a0e7266ad9febaa |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:1dc042543b772643dbf3b97d63654483537b18301a7a027d9f26b95ee819b79d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:51bb0589a6dc49e50a1d7ffc4ebe98c776c9b54d9c8b40a5f093896dd501967d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:500996bc26f840c5dbfb51e494d9c12623d0975a2cf963ae0d6f3506616eb19b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:8b4944679c048b20e586a1f4e65d305bcc4cd886ffc19fc0a6d1d62036a9e42c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:053b41bd448a7a682f22a214fb5eade913a7158f59edee2c4b33650c586ffdb0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:0ea020800afcd163a4645922d743c3fd33bc60ce20fc17df7a818dd791db5a2e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:22f1352b956350314a102ef95e3ace81ab9113e42604eb30af3b439183e74dd1 |