Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:fcf182ec5daf6e4dff73bf3caba711983a2e311f543db570a8c1fc86d03c8318

Manifest digest:

sha256:10b97d7b065cbeee0285be1462862b1d2b3613c835efdc4bf97293ec19c3676a

Size

134.31 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5b5983673e9c902c13427d06185541c8a36dd6f45501e1757dae8842c8333ed5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3497994d4a980640875bdfc746050fe15a49eb80adf610fc226df79c1b8c3d1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8b0f99ce6bc87f1c1214b91268efbb53b4513946cbc2470086d91de5d17f7bb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:be0367baf617b09a564856c799607ad2fd8705692f44cebde04e315f35697d0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4af6e5d45613ac809b71f2ab05ddc3203d44f8da61fc559c9c121473b6a2f4fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:94dc13d5eb1f33c93c5bf30ab2ab4d6e276cf7f808d9a77227003f379d687e7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5827d7fe11b5b105b8363b67e57ba71c6c41d17564936521e1dd55c8ba1e118b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:350b5e5af549dde9447695f5ecd49b431aef078eeffe76c945d0a513a4bb33a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c5d42174090487aa6831ea39c12c01ca1942b2f660105e54c8ad0862a5f57a57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5ed8c1e998154b8d5b1e3672a4f8272836d8ef29ab719a3fef8344c6f821d740
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5501b169ba439728c37c10b7bb6e93c809442eea4c09e0c10349274ee3f66dac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7e686c508369ee15c5aa17f41281486e2e1a2a3d4f72903171a9976bb86ddd09
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:bb97515931e18f0e59a90ea9d7690abcc7914c456e7a321b2d3d27b6ed7ca10b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:5bd0c0b9a37bd1f6d8170a9aa40f233308a9d0faf7a93783ec233fd6ad7ea745
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:055b6178df8a143fd6b1089fb25a725a2cc85710bd56a90ad304b960a94078ac