Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.0-alpine-dev, 4.0-alpine3.24-dev, 4.0.6-alpine-dev, 4.0.6-alpine3.24-dev

Index digest:

sha256:c13cdb9071041585e0c2a1b92ac7676a33308d4ba8c6ad0567c7ec3d8bbd6cc1

Manifest digest:

sha256:e2b3a142364b00827f067b514eab28e5c04cd58a1efd4c51e8113b1fd66b849b

Size

93.71 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8d995ba95e3d56fc9427ce6570c2be9513e74763a4763796c2d61474ec98324a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4b570cb224fba57970a65ece142399f5855db8dbcfa29e014ebfd2a3bd6cca71
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c585e6e17e15fe8cae6e74c9c52941aa978d0310904ac3dd0eb02e431bb17445
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b263950b1116e617d7c025735d84b780d47874295f74bc4a9b33f614489e4f17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:395edcea9fcc1b498595005d2a3a6825ec991853d96f41c9bee5e661b37a5588
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:674c4f455e738cd563a588365383a470c73219fefdbe56e565d579334e710da5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c69ad18b3366322132e5a31e46cb3609ae11ca78dd3cb7f9ca82c965264e241d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1b099e1ccb3cb75d5e81730b84cfadd81bbefdab60270ce4fcb511ac848230b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:478a29b1d31c855eabf389b4212b90f464d055b6c5acee51c749d785b4624a5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d5081acf315e8cde8dd569a0af330138729a474bf176c2014c558968d16042ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:5f8e4f2c49735adc5c25f9cce744eee217eb5aebdbf1b56c220312c903d17bd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:735ecd1fec9253c477d9180e63acee2257ab61f0da192652c821ba8eb5570ba3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:60cda902302ebebca4d485f5106dce94e474787e87dbebfc0b332537225be4ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b8879ac01b6aee9f30346ae62aae41147befacf5b0d37b266cad8c9270991cdc