Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-dev, 3.4.10-alpine3.23-dev

Index digest:

sha256:d7011f7d7da124471fea4ed185c02781cdb3b8a75d0cc9364832699053a73876

Manifest digest:

sha256:3336ad5a3e331a85316a08ad3fe9631ec9b794fbec7d3eb5d8ec2102fe08b130

Size

92.88 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:f16c8915b8c99dae21b71b751aa336290e27cb80d306b10e3e1e1585311a50bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8d9dfa4dc1faf7df05adbc4ffe7e16ed3814d9ec68eb71a854147d3aedf1f2e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:084c7490403069b00a0ac7c4660049eb0da46f5a2f28c445ad231ef4db650233
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d5663e821965012f8bad5f406be5d637e9a817ed2b40299a1fe001b4be114315
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:af239c49a240aebb7e7a37f4b4d119d9c200cf849b906bd3f70c26ea9296d739
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7142b506d3a4ea320a7b9251c692aa2f1527fb43316d5f6d206323c551533b92
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e1f28ca42640ded56d6cd5753fc046c1fbdafdeaa2d24e1f0f817ffbf2676356
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:0674da5b7074778118f6145bacc307cc8fb76a9541c994ae5ef39d519687a1d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b3a86bf3718028cf9ff6ce1c60c55ac80b6c4d47be671bf923aa8afc11e30fad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9edeb33aa0cfea289585588725cac958779bb8579e7cdc2f9bb3d93177fd3bd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:022eacb86d37970d50a8ac724ae412c73e90dffb338986ee1674923ea2be9621
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:55ef009da4a961d471bed4c8db6c0b24142eeceae48e4ae44427109e86314732
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:82899064cb60277f67c421c0a2eb6214753d983912db4de58a0a786ae03d25dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:059e6467de99324ba320b3040312ad2af679f3a1a6c6c9fca43cdf83e247aa11
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:68f209e700fe092c3f44d1dc77b23724b5d6a6159891ee7ebcd0831b452d0079