Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.6-alpine3.23-dev

Index digest:

sha256:7ac0d4e0717e849ea08787df949b23f8c8bb0bb6cc2700338464e1a58c7c5acd

Manifest digest:

sha256:d07bca7b453c7478c9970a00993c710e42dd1e31359e93c2b54a5362e61eab0e

Size

93.65 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:95a54f98e66b6cdffc7640468b48d3235b574f554f3dbf244b44adb8dca13805
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:452fd03a6feea6476eb66aa18bfa1f7d66cf98bcb1f4a5582e87f112961a1256
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:90d466b5ee9b222de9464987485ec55cf22c6f35bb8c2bc8544b101932152f92
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c3bff4a81c8a9df25b38affe976ae2003632d5e244541fef0d38e7f229ebc193
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:fe979de8b06c427ef2bac14b8a6b7f05762b139c871ce9d372c09eac73e5c51b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:77d6e8cba12b83c484a43349ea19ff1e3325059fd9a14b0be8a03c39877a3d15
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:fc853230c09de73e41d944ad8ecd439ef56d96770287e5d6643a23422e8b5f58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a635e58bc8a5f7d44e79da14f77623579e1782fa880aa62092182a37086c0187
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3731a3aaf7cb5147ac85afed34b997225a7e01a14adc6b85f62ad23723ad4d31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d89a452c83ecbfe2a5cc3c6eaefad4c2c604348d1da890151523c6c42c64b044
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:878e1828a1dc5e642d69efe7b97ea77633c95fc867402a500d155deeb338f5b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:256b003ec1f9f76dced5363847f4d23f7e4404ce439432f20d4f53aa7aab263f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:efab0c74eb3768b3ed3352dd14ad8c10d6b3be8f40d788b9375535df06319d37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:1270ecb2a36e79e010d653b66db0214d6dd1a491a44b573a56d1c3e67fda3173
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:26ce3acfbe8d3a5894e3f5b95ab4811fe6e4f4d4e98f8e65e21e5ec7634f29c2