Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:0b65e64f6d75422a8518b7df6953b9b30a7c2c22300acf69e29d34c5ac8840d4

Manifest digest:

sha256:467d61f2390a9d3fcc9782bdfb69c73f170812bff0097accec16e51553f55178

Size

134.31 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2b6d29d4615ceffae6486719b7482340afea38273aa42f222a4ca927e77b0eb1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:6d0550d4f5368a39f81c7afeaa5f246ae919f17579c8fcb2a9b01aeb27d4a569
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:36cf754836b759a37ddaac25fa462c6b16f53916048e84c4c82cc6a4fe175f17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f7dea532dbc5e378a765a607fbfbde6883c1ded4d9e3744212ffdc728afad482
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8b2c82b541eb14a1b314c82dac2e49d2aa49f4dbf6a12ac00786d168e175bc2a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ae273b66fde1733ebc75ca060e7c6eb6104927ad29f400cff4b4f380255f4b82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e577a1d983a67296c1d4c25837cdebf669ce57980d0c6235d09a71a44529979d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:961158b46e8441a0813de8f84fab481be813c19624497f7264ece61660d17848
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:d8133c92e045d64aaec68c844e56850fc2d1e5c9e9920b52211dff3a0bcc81a7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:fe40198c5b9349545cba05ec12af8b7cd6a379875645117f06562213300d03d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b0e25ede70e35d16aabdab98fe16c27479d0c70164fd17ea127a37f81844551c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:329d7d5e14268fdc28dd4f1c57566ddc104b473e14b5784547c7c4a775650966
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:adaf701ca2de4e99e5f80c6567c4a93b7210181f71c910a56e76f6776f16219e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:cdcd6059a5074448c0d8196b19ca166ee97074e02a3f31ed6729ebf92cd24d0a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:95cdc9e3f5cdc45e31aaaafe51d853b15d049eef730f366df0ea0a8c710c0771