Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.0-alpine-dev, 4.0-alpine3.24-dev, 4.0.6-alpine-dev, 4.0.6-alpine3.24-dev

Index digest:

sha256:ae5023b242af838374bce9162e34ad1558d1c3e030fa1182f8c7f944f1c35470

Manifest digest:

sha256:4654c965836873d0f3416bee2c7ab25ec98060f5eceb16c431cac853f38fe0f2

Size

93.71 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:25762eaa1143e2b407e5bd9ff7dfae4e00654cdbd5b6df3153f0cf1c2ba6d083
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a6bca914f9f155f906270d112a04800f00a0b9044bded3d0a484ff406a8d8ddc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6de5013b04034530ce450bf07ce1ebb81399fa75d37f6142d62475964b77185d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d6464359040beea55c9fb766caa8c2995fae75a34ca9afdbe10eb36a8fef760f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2541d13bc478dd028864a2e6b0bd7d634de96f50111a3ba38a09c3482add5b73
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:dd2df5be73d5e9cd9735e7522c95cceca62e020ad77229a2a683bda63bd9146b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9a7a483e4cfc2f7e2f194b84ca6fbe1d5cff73eba47dee56e84e2877698ab0ba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ac4558016446daa2af21d38b593f9b06c5090a2a428e5e533b31d6c6e882d8ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:edf2a16041814135961d43351152829bfd33f63eef878bab370ac6217f403ddf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:28ee94abef59b4827f9ef7e4ba892494a22e7e108b75e87d6c6e8a7dd2c0e0dc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:94f5865c9abf2769fee8b173e6ca62f81fe3dd1ffa24edf3d0c6187af5b5a6bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:83aaf6ae10a277eeacbeabd0b984cd843ff0403d2b3f31862156dd34005a526e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ba73c27aca5aa4d2a5f4a2525777a059fff5a5fdcb305e73bd4384f1fd98e4a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:19184d9e9485d102883953ae2b263db640f6d4fdba84e31385c49d169a4c600c