Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.7-alpine3.23-dev

Index digest:

sha256:e7a89736509763f6c5c789284fa6072043f6b45d599aca321d2f43d2d60a3283

Manifest digest:

sha256:c5aed51dbc212e8f9fb9a2713921eec1868af497c76f002c6dc424da9f80cd93

Size

93.74 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:397ba19d34b3d7948e146af5698f8e4aa12faa6aaadff73f423faeea769b6a28
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:6ec53b3c0ab6a7027c6f8428f6a75838e2a07f634714795f79e4b7a102922060
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8e4f4b2fa27e6eb8537ce47e93b1222575f779f4902db876dff64678fd54b414
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:795121f66d06e92f78ca6a800c3c4bbf0cdd7d52db6709d02f375718a50518fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:09e8c711f85ecb23bc5253b97208d0b79efddc9de2e78026cc16c41725c23665
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:fe78fe88990619d899cfda4a8f31bf56d4307af4eaf40c0e2cf37a3ed0200d45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d6fd08c694625987af364b7ed7f746d7a417e05f999ecc8ddbb9c0962ae3e514
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:49d294a3178f272a771003a265aa3c3ec07e7a984ff0dcce7ef74e62c2305f84
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1031825787e4b5f71c0f2e550bdca7f61622d1dd57894a89aa6d485fb75a7d87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:4708bbcb4db7ca6dea9686b38703c027731f5ace6ef5c79b6dfb22cb7d5d199f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5117d3218a3f1ecf62c2a72a48407bac6ad088a14320c50d1dff629d56922e8c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c12ec63dd470f33360d89e778c40f586e4309824f071e3bfa93823de2f35812c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4f7df6abb898c094c934d5bd27d36a9e4b165a8e1346cc315314d7b5c5d69dde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dbba188aa3fcd49bb15de0cde7f5c24f9d8cddd4f7867a9ba65e3c24cd54f7cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:abc161d517ed68a7dbd7190de27eed6002238fff019412415402cedf90460c6f