Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.0-debian-dev, 4.0-debian13-dev, 4.0-dev, 4.0.6-debian-dev, 4.0.6-debian13-dev, 4.0.6-dev

Index digest:

sha256:7c14d4b052354e0e3ba8a1978ec393725dade75a53ea9a68959dae7fbfe21ad1

Manifest digest:

sha256:279ba108e2ecfe2e4273b394d2ae0f750bc7e9fd3448645e23f5422fcf7212bf

Size

163.73 MB

Last pushed

1 day ago

Vulnerabilities

2
2
4
24
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7245c805e0cbcd7a459f54b4c08bb7fabb161643684a5830501120e80c67c2c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:cd9bc3454d81939878a1520e809cc036e37ce8270f2ed8b45452897500d14803
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0d095f7c889dbc1bc64be7ee4e6f6e4ffa4f1ad5bd8669e294dffa3f5348bbbc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:893c1a39ce241c1cc32bc561a33b1add68adab7b1b7a17743589495e413078be
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:13b818aa2bb3c9a83aada4b57714acd293cc7fc80ab0ed44206de402e62a3834
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5b29b5e62250900a6d8f56c4097c1fd7f7ce42138e75d1b8019c8b9bfd4089ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7dbd6240094bb3018b49de2663d04b379354f297d148c5f7e483c5e1299befc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:894788e80dcd8c7904d5b1401e95aa897fa45b550015657be9f80fb639c1d040
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7b7c86ee5011ede9bbfe45fc452aa0a65671e1483a31141b98c6acf629519f0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e30bd1fa924cd5104630e255718f0f8f6eb3d03dc8cb7784d25ccfcc3c29811e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:f25a1e2cd445ff085ca9160ccd0e0bfa37bd221d91554ef6f50dcb80bf03141c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1d815a7fdcebbab6b137f39e45900e972265a1b536d79aff359b72c125a24e8d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:aafaf3d53c2f115cb6cfb3a60e1157ddde15cecb04cc1b6203059faa2a728846
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:a661d83b1c83756a492493ed780f3b2d0fe3e6342c44793f7764978ca986bcd8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e749cc511ac884ce6db830e384b05ea3149c72bfe0ffb75269df18a2ed3fe85d