Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.0-alpine-dev, 4.0-alpine3.24-dev, 4.0.7-alpine-dev, 4.0.7-alpine3.24-dev

Index digest:

sha256:49090aa8e246e7d9e1fd669d8d0acba27bdfae8b4cfb8b3e5a0d7c56491b471e

Manifest digest:

sha256:a46422fb42ba325d4842f7f64e022ac3d8e4aab21338e3be7f5f75d73c51f7f9

Size

93.74 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:48a42afe23aadbc49f1a72d541a5041035e08804527d2019aa6ab4462e189d43
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:6a387d9a20acb60f54eebe51a46dcd8dfd5b9e38f9fe80302d0d935f3671a711
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f00a5d659f20460fcc67221b99252db9752c3b13f951d0ec68509c0696417648
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c98031d6ab1ec37966732114906509b94f73ea78a3537ae2f1aa7c85d0d11e3c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:6bc2c653719b88f2a5e17cc27095100966fbe2d0cc2f78e3aac3b2ede929403b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8dfaf277e084e5c9b35f2b93c3c3ac35813f33421d01fa54c75d1f2f961fa1a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d4bf8c8bfe061dcedcfc5ba68a60971405c280fec56d665d74e75954529c33c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e1d8a47349361574fffbfa9f9f44443fa88a7bf743c3132125169b7a435c5b23
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:36bea26a4530cfe3dc8565329de8a614c3472dad5ba3fae73d6e686620af210d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:fbc0877664bd6c01033d88eecffa52bb31c07b8159a4f8fbe8a9eb309ce9fe39
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6886a840a1631bf30b65752f7caa794a07b3de54463db13de3c8f6ab4c0e3308
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:74166af4ef80eaf3f7fcb04313445e80cbf50ae808061bdc2a73fdd60443cad7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dfe2bf656f479836220bfd097b3c64b6489585fdb8f3c6ab41ca6422b9e67210
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:39a00771a66031fab0f12a984b4fb371f472b11b4ac710992be8bd12db369947