Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.6-debian-dev, 4.0.6-debian13-dev, 4.0.6-dev

Index digest:

sha256:bbe2d124b380e5a381d50b9c0a636980bae603d36359ba6d2e78ef069fcaf742

Manifest digest:

sha256:855461ba01de4f372ffaa9e32e892e1832d5eda86a80364399f0fcff7c2b3018

Size

163.70 MB

Last pushed

12 hours ago

Vulnerabilities

2
3
4
25
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:cb39697d2dda37ed0c98ec191d6b05a6f61405251f6e6b7af06a7e8788c36247
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e6189f45e25a804ad2ca1601068726c8a30de208ac3a5582c68381eab3671c4c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d390ce5241a1411a881b674d9c83f6746058a91b2b1291eef28214613477b086
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:305d6c257ee640582049e41674573438d112a55a0d7c2390fdf59875bcc8d78d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:29ea54c102763eebbcf2cc7cc680fdda0a93f17454fd8ef72f9741c1f31900fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ebe5e2b41623f398aa98ae42857512a8711020ce372ac7f16586d786f46aabfb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d11ae055bc08ba8222a351f96f9484eeb4684dae530d1670ca705591d6724959
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9c582127c7155d17252f804a909926d558e82002d06e9f8488f41bf923789958
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:07e2e5d5f6bb857225fdb0f8a7783421b6eaeb1ec8ee8302225940d3f60638bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:264d24b8e2fa68149121c323c0de468c1f8e9c16f4c52a93108577b127d5eda8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:9e0566754de77efe8e281a65c8003ada9f2f40746cb6c0cd2b8ad34a195bd63f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:195d05b9f45ec7017e881b824c5542b2dc963aeb07b6447ba9b8d4cbd0d82e63
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a2ef8f9d66f2dccfef4e65bfbd91b63336a1c20066b36566793660558e8fccf5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dc64c6625ba6afc6140db9ba2f29af10201a7075fa2d6843f886dd783613c2cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9b53790f90ac4d8d99b0da92edec8baf6bec4e68a82c2f37ea6488a15581efc6