Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:28bc767ccf2b7df18375ebc6a8ee332a760ad1aae99cd841244839b46b953dc2

Manifest digest:

sha256:264f22189a0947f8a8b1e82afeb853bca4cacd5edf8abdd0d61167bfac228a22

Size

134.31 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:c53b28cd36e9de702dc9789d35c34a56874f75e0c17ef4fe025a168a3dfbe607
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f8125b685d8e9511614b264e8aa78a84eba3cd6ff024e145568305d1054121d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f86d50e23381c8a5cb574d4a1005e9f419045dd3f8025908922311debcece324
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:66b8f83fdbec81cdec9fcd3645a754143ec73dacbaae299c851367ec92d03c70
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f8d50fc075b3f181ba48f6e483a415659d7e1383c4303cf45d61a267d6c21a3f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:fe6c2b9a5e0bcb8c8ee7b9c22b57108923d39c13c8c324d47b19c6b8fe4118b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8c420b38036af3a5e4ca80000cff439375419f21cdd9d9d51717cf211c14cdf8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:334919b68fc232d637359146e6b467275e97c0a8f4cb444c1f6c9dfe1799b30a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:fbd601337f8e4e473f558803745d01c9b67586074cf966ca306708c0dc24e878
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:76cbf9b7e56907be59eab05ba1303f70b12b453935f2fb9f1890d78c9bf92033
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:deb4c0585c45206589248875355d036ff6cff651838abb5a90e0ff1e2b94b6c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2baf4c5c126da9fe3bb7d63a643809ff0d47cc35e527244dedfe82e53a8bfb89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:16123410b62d8d34561d44b57cd519537d24fc0a46664acce70969069908f3a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:91a597bda5863171a56d0bc0c3abe10875245667dc5b97a2f6219b0fc233b0dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2f1d4cd0a4f9f7de8d17de8b59869f5879697af5c1eec2a4ec5280eb5056f534