Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-dev, 3.3.12-alpine3.23-dev

Index digest:

sha256:f15c13358cc90d059b3c2aa5060ac27c6a5f72d029f92d75b5fe7cb90b930f5b

Manifest digest:

sha256:a7edcec3b18f384862000efe9f4f71981f4fc4d21bcd9736bd6715dd6da29aa0

Size

93.25 MB

Last pushed

3 days ago

Vulnerabilities

0
0
3
3
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8804a9b6fd2b3d8f4d7e3f3a0739ff8eff989444993f7d1886e8f95aef4de042
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1fa54717c73f7baeb85aeb042e841c4e8aaf7eaf7368dc731081cbb57378ced2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2ea373e19ee45a91eb4e80e83cfbc54bd2100625ac2dd2b90a69ac0c2ecccaab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9a214eaaab7b040d5a0e64f5757afc337a80f8023dd9ed743103861be984cbc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:bf8e9f080c169f3555c92cec068d83fc84376e3edf884d34d20ce1c4c40d416f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:81014fd266306c29294ced4d55969b7263495977a85fc2a14bfb5327b897140b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:58092e54251fce52a71129dee28faa2bebfe26782650cd23ac3b336bac43c90b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ec01f8f58b5165642ee56d52ead77cb0dcca8e02e203ac6acec29b16d0c98a15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f9bc88c8dfc8bbb0ab3abaf04e4f4829c61bf0d852a6701b0669c3820fdb9257
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:65845c5ebfdb250b30d1a124519461365e88e43bb365eae60e2cb0a557622928
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e0784483c51e2cbc24eac28d4ea305f9218bc707300fd6ca12d49dea9d15657c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a7e99deb74209d2403b5e7f37c59fc016101a8415ae4c47eab647d901d5d5d02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:b1a7720ec58c0290ad38321d473684f42ac398184b644dca96e17f5b4eabe415
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f292fc2e93094ef22eacc1d44a7658a4501ca075dca14c1fcee4854f40b9c933
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2a56d9cc9863c1ac74e2d4a1eba7a4cecac3ebfe500715ba4768d5cefcca87fb