Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.6, 4.0.6-debian, 4.0.6-debian13

Index digest:

sha256:6c5a17b9a7136020b86e62263f5e3a78475ec9048f073646eff8901628db5e26

Manifest digest:

sha256:1fed794f792486a953befa957959de6b33a2ebfc6be647c0b4583a74a26ceafb

Size

22.60 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:334654396449b5ef5aeeaff062d88cda268dca063702eb5a11e3a740956d8038
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:64810bdb2dbcea04122172400d46f88c368fc7d929805da244b4e1dd7e723112
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:eb09e78c235eeff6590c184298fbb01cf67a1b06f90a4b00765edd980584ce93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8d137200773e62e82bff5652c3e6a0c21ec298a91324dbf150672a3247ef6dca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:887db0a4c356e57f051158628a5ab28dffc2739922acb57898e0ff222169d87f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a92fbf2a938621ab7bf69639e5d45346f8831eca4fb933f84689e86441cb4abd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:04582671e23cddbf486037146b6b23c56d59bb7cdffee0733f33e03b28bfc4fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:61b80d3ea1d9dba84930f9b52dd920dad798b4c08600bdbb2069545c8f18056e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2c12bfcc9acc739421827e522f1c62c784b48bf63d40c39ca5a8d568be8dd389
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9270a1f1d97a809266fa8a32771823b29b325928c9d4ef81ad5723067568f5a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2675eaa07a9c40c011df8f2a6a01f7a47e10cec5b390f7068eaf82a181392db4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:acbbbfb9e939d7393d33e88d5e6745d0a2d459d0676b66ab9efb4a119849a8f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f646949b4a3366225d6cec5ea1256f6417ddd3cb5b4e36ed51efc9e0a16b12f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:cb722f08c8f5fdcbd172d87453f7477032b64a82077792d9f16358ee1cf568c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:d584ad96a160381d7e00293f855992f3e318897b1680ba4d0ace8bf9a7b455a4