Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-dev, 4.0-alpine3.23-dev, 4.0.7-alpine3.23-dev

Index digest:

sha256:0b48e70a8bfc664555b8d12349f845ab5fb0aafb4db16e18458658967b984719

Manifest digest:

sha256:73816b5e00a412c69141974b80a5bec35b2e7cf4aaddf2ff9ed04340e4b4e5e0

Size

93.74 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:630c93d74935145ca1f98462653df0c038df761c34aa87078517b723c9d859ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:88364535da2f5a27afd1b05dcd5a2f5851dcd47352fac3402835e73d0c9ac363
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d851505e6530d7efe80f3aa8ba6584d64a1d3b80a9145876c1602646437e0976
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f3be0a32c2689658f29a30a92837b2cdf6f359330b3966e8886cc650769e7479
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4eb4235bafb9699b16014429fd9381082ff0772ad76e30c795f4bc54b8dcf703
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:114c07bda9cadb061f7224e2de93d3745d676dd04d46e7b63f1e004ef4cb3b70
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ca04d9b2517d5098209d0cbc2dc4143dfa2596eab7c123f328750c7721e7a571
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b72f8ff9ac63a7ee7f87a1adc68b9040a4859d41923cb6d9754abdb0b7c98f92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4e35ce29037985ee008a580dbaaf018a8ec5004c379df0ec74632b1eec29d3ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7fd6cde002139e32046cb011dbe82b59b7011a34a6e7920b0fe4f4263d8a45eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:57995b8572b51720f9804ba30a5fe95ce60e5b0c7c3e5f8b0ae2401851dd077c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4224770cfc38b1c521b2b015f54adfecc51846576047e56f8989a5018c0c81af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:9fb28aa577ba2829e2b02e1b2370cf4b92f6ba9d916757104c447a617f7b686c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:a07baedf05bdbe7cee2ad36e440b36fd19b75e759bf3930e0681cd858a6ad682
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:98107d1bcf2ced834af343ecb13f1fff389f42c5d7471c1f20ffab6d545bedb8