Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.6-alpine3.23-dev

Index digest:

sha256:2cb0d4a4e3c329155a73c23ec8cf51ce0f478595b28bba406271b6e090a2fd20

Manifest digest:

sha256:74c3ef73852c442eb2f31405938831ac299b0717f197a57c32f15181c1bcb78b

Size

93.65 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:c08e8a27567ab8b7d0fe9fe5c9b05d85d28b5f97ba00df12a7fd6e0d6f825791
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1d685be2b992b245772f60f21bd5c77ae5e9538d08d1e3379d0f57f7d969c5f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8c6844a0133b7659837417c24996afef2a5caa116bb9c85a35ef6fa85f33641e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4cc55622b4c360d6fe4b8b99b6a2af139e7a5f20d16133b0a2981cdbffb8e56e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:eb7df1b7acf766114b1089f2b3d33008fb7dff711b5a37040c1201af9f2fe500
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3fd394d637b484017f2a7d0c7784c1dcfddd28314c4f614181f07d7421df91d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:edca6c2c5077caeb6ef4cb8a875578dc7d29391d3aa8f0fcd5745f07119c3382
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e41fab114cb68dac96e72db1da74659a8cb4d8885f099f806fdca14917febee6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:47bbdb37d7b191fd1f80770ad5c2739e11659d6bd983afbe8d1fe2789e56bb6d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e6113a0c299ab3ea9bc1cb8bbbb40025dc40f2caaafb052cdc97e13566284d66
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8be2a6567e598b71b7bc7a10fa9548a7a476b33a63c9552c01008f3ab7883307
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:141b188c7293a4357a9edc94f15bd96555e545613d4927c3b35cad3073936165
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d5077da0998cd32f6ccd48f45d990b6406fa9e954e63ba11bb62e62b2dcc238a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:5745d257e6659d853c45166c56ceb7d4e2802c789c92c03c8715add50ee6d7e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7c468b8054dc94d55c4c4a4ca0c61b8b64d104e649dfe87d210e582132ecdcb1