Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.3-alpine-dev, 3.3-alpine3.24-dev, 3.3.12-alpine-dev, 3.3.12-alpine3.24-dev

Index digest:

sha256:66a46746215dcecf94d17f0c4828a43712f63ad18b194e2fb5afd40ff6c42154

Manifest digest:

sha256:15b84fd944ca8f09830628d8a4361e43b1eb99f8d33cebf488eaa151bdd90e46

Size

93.35 MB

Last pushed

4 days ago

Vulnerabilities

0
0
3
3
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a79f0d3bb86177d934431985198d6aef64de11a44b5ecdfbce2cad241d50a86e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:20eef0a9883adb3c2e5028ba42ca94f03522a3212b4fb14e8e125563398f611c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:db7fbdd4e14a0bc96d52741f1afb2aaf59605558e400fa53bc5f0b9d46fe84fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6b648a29726a1ef82fd5d9f9757085a116984ca1a18b1dd461fe1544538ce646
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:eb4961fe9bea742257e5670d426b548018b7c8771063ddddcb516a672e84f378
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:02cf3e2ba8645d8136b90601c4c734d0c850bf25e414007d5cf10874b8bea602
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:304c23f38b69e3861be3f565cd7f808a772458a18e0e539b77ac92302ad328b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:cc1f51ea31194f94fbd5d3f78fbea11b1fbd9a081539c4261a49ef09d86f101f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a45009c927237aaa4555084691033337c3426b0608aefab43f20d8142963b711
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4a6189c9563452dbb3b66f108ca062adce1435da4977a029ab01e0ade81f8db4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f60824e3d1e28d4496c56ba3189499d000e8d4c5eadab09022bd41fb1a3f2acf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4533a2e3d13a0777655d9b5e0af1928780b338e50b7cd69e8b398dbe128db572
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:170967ebec89ea7939b4e95ed1d3cacaa4ebb80945f506b210ffb742db856565
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8401997be5fc2fb9e45433898351137074a9a2c0bdf4fb1b0c8ac5dfe24e3437