dhi.io/ruby
4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.6, 4.0.6-debian, 4.0.6-debian13
sha256:6c5a17b9a7136020b86e62263f5e3a78475ec9048f073646eff8901628db5e26
Manifest digest:sha256:1fed794f792486a953befa957959de6b33a2ebfc6be647c0b4583a74a26ceafb
Size
22.60 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:334654396449b5ef5aeeaff062d88cda268dca063702eb5a11e3a740956d8038 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:64810bdb2dbcea04122172400d46f88c368fc7d929805da244b4e1dd7e723112 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:eb09e78c235eeff6590c184298fbb01cf67a1b06f90a4b00765edd980584ce93 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:8d137200773e62e82bff5652c3e6a0c21ec298a91324dbf150672a3247ef6dca |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:887db0a4c356e57f051158628a5ab28dffc2739922acb57898e0ff222169d87f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:a92fbf2a938621ab7bf69639e5d45346f8831eca4fb933f84689e86441cb4abd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:04582671e23cddbf486037146b6b23c56d59bb7cdffee0733f33e03b28bfc4fa |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:61b80d3ea1d9dba84930f9b52dd920dad798b4c08600bdbb2069545c8f18056e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:2c12bfcc9acc739421827e522f1c62c784b48bf63d40c39ca5a8d568be8dd389 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:9270a1f1d97a809266fa8a32771823b29b325928c9d4ef81ad5723067568f5a2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:2675eaa07a9c40c011df8f2a6a01f7a47e10cec5b390f7068eaf82a181392db4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:acbbbfb9e939d7393d33e88d5e6745d0a2d459d0676b66ab9efb4a119849a8f6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:f646949b4a3366225d6cec5ea1256f6417ddd3cb5b4e36ed51efc9e0a16b12f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:cb722f08c8f5fdcbd172d87453f7477032b64a82077792d9f16358ee1cf568c3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:d584ad96a160381d7e00293f855992f3e318897b1680ba4d0ace8bf9a7b455a4 |