Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:bb1e303081b1608a339f59677c52c9a7ab5ed059b2e25f3b4210e3b22bf8f38c

Manifest digest:

sha256:73e0c60f0018fbd3c3bb79b128602fd51b2c09807f1c88df2ec653aff91d2c90

Size

134.31 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
2
11
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d173b4b0ba0ce012300d52b1d7f87cd4567b8787ffc71aff959ad1c7587e91b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b7d877a481698314dab8963c305f8950c4f7ea212e15913e25988dc6ca135a8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5318878ce9ed03d3f5ef6b759a8b75b342459dca086a904b9336f75fe1842eda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:aa8b36eee5bf0a4a87d0202e0514c64c332fd75417af97e2fbcd467fbc4f6e28
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:0e7caec0613b17e88c94d7def2a6c2ecd003723ba4cd3e93a2d97270c76b4420
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:cf5ad412299ea41d224a2beef5969ec9824804e0d0eedef960c45ec4747c6ac2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b241ec66b7670898ccdfc2339b554cedce3038c2e6303ba2c9d500ff5d97132c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e1de6703ea98baf3688ae9505cf830eaf33da219e915422d2a049a3711b26b4e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6feb0e431c2cb06f501175e962ed025747fd9a060002ece950a26be4b734c6cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7b7142f05a07a907de3c2977e54e73d0c346866c9f624ec405526899682b84b8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ca8d172cf374fc1a59cab58df0332f30082822f594e5e5df917ea6b7023921cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:54a8416c45455850921f466771e8988ec53786efd6fcd7d586c083bd7c4ce054
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c0fde2942e5da0f84f062dda217bb90beca9501c2d7b2f246f153600fbce87f6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7e6a2710572c9fe721500c8a42a18b3213ec64dbce3d131b35d9561560d6b71e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:96a3b11149335b15fb32b60a52669a4870dc7e7ecca52920fd1adc2308e6579d