Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:d3c6a592b533de70f6ce88cac0827c30051ce17df4571d0c41067716261c4994

Manifest digest:

sha256:654e24c35fa5751f1cbc5aef9ceea4309bad786591e9609d26d3244f7147db81

Size

134.31 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ebabf838dda215c171845133092a6d7beef28da88f30d97f018d4e46f540a192
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ef51f438ebf4a56725a84bbc6c97186bbe076e8c50abb3ebf2ff73bc0955dbc3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:dff929b93be6e7dec5ddb81f385818fd58bd6286812635af6000825e9925b3a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f3d51c8b0020ebd6e57f6f81975cf902ccafa03b4b0bec81c1b9e213cbf0ad7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:dc0e129a01f232a241361a02adfff1f3885b045ee3562ae4abf5285e1060b0c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:e739844d1f287daaed7c763313716a5fe9c4761f241b5bcec088d43856dc2409
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7045268f7609701eacbf2f24c96eef712195656874cf7efb5fd5ad84063c5d13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:25d3eba2cd1170bca3dd6fe777925de538e8e6ca5d8d24f3a5631a3200f67a62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c1d27328f7b72f0789df20373761357b2292947402de926a0f255ac52373b6b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:2df3b339b25367ca2316a14ea9f797618c425662bfe33198bb8fd86dfefc4d2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:c44742226ad88642cac94a41a0a788425ae8bf8395e2ca14791d05844da5f576
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:441b31b8bf20f7f4c7eb8da5167a6948bc98bd83152f552e23f032baa267b5bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:6797885b2cb3570c3d390d687c1a36990968c0b8e6a60b64d9182fe4dc7c6d01
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:290ed7951aa4df551a393a638711d2087ab7ec41fbd2b971df06d4310a8efb8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2bd8ee26194a61c4927726ef9c1427bb994e8cf5ea4e96d3d1689f64a22ae100