Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.4-alpine-dev, 3.4-alpine3.24-dev, 3.4.10-alpine-dev, 3.4.10-alpine3.24-dev

Index digest:

sha256:f8357d934b8364cd4043b717905ac97ef203410988c03d19f9d3b85a166109bf

Manifest digest:

sha256:8b065370794cec99b286e69e2203d6a20a62c5d54857edde64adf203a4641d70

Size

92.93 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:83ed4d876caa3f92bca45d640dbd16af90f7626ff01f1101d05580b9b06a543b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d566daada85313e0904a26ebba93d42411bf4f5598f0fa539b9224731c6999e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2f8ce969bb37fed84fe3c4f091830e2bc8a52f763a318c6d04b68c6631a63d55
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:83f733c684404c4b8039e06dd7c40f79b358c05e4aa0ed43f3849f079ab4faea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a5c7d7d01ec3938582ffc6bf832de8eb734feb1138018a4f464e17c0c55d8918
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7caacdcab48d76a89df73dc8b44d581ad60ff4739971e453e6980fadc6b3b8f4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:20ee2549dcddacdaf45195810ba17d2b359831e503c556c3af0abebd99d09308
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c88f8078e30af430db40432b7c5371cdebfb6fc3078f3aae41fc0f6a8b103f44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:774a96605b73a81051b6585384b695316b20145be7de0a438867023fdd29a0ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ee3579c1849b21fa9c61bb8ba089ea68007cbcd16bc46e1979b3984b9e80dbdd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:764fc4ae42ad0e92082f7ae94c67a98dd243d7df0cdb873369183aeb4f7aafd6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e5cdbf8ff8880f0590cc96e8654feacc8af82bc4058526aade447c1d05ff0fc9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1a18330c4c16fb81dc573a9f4079f40c9570b930d3d5078c9cc1cbf700be26e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:6d81786e99c016aef3bb6cccb78cd354d1e98538396e931cbfe06e5789ad8d2d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:df28fb0644cf531b8bab370247733e3a1267b57e76a4de5c6404ed38d99442e2