Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.11-debian-dev, 3.4.11-debian13-dev, 3.4.11-dev

Index digest:

sha256:d13ddef46d64af400068e75183cdfb262575f2ca0b74d34748bfd3bd2e7a8681

Manifest digest:

sha256:770e68ae236bc26c8a7ea438803faf656388959efda919b969a82e7eeb7a9290

Size

134.33 MB

Last pushed

4 hours ago

Vulnerabilities

2
5
1
2
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:912409f478b9b83ea64f236a0fe8f5e79a2af113b30eaf607fa7c691b9a7a31e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e629b6d7fa9553a030b19e0d05cd87a0ac43a6d15a4eaf970313c506c28ae22c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8d990060cce1fd5b0fc62070680abb301492d6ace2ca9d9e4b7efba194934f38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:10f563f3a1b6192e7f6123676404be3cace5f3b29eca72c4e9c680d129f3fa71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5596f3ba272c2e8fba7b50eccef07fe68d68bb1cf85700772f29a81306eaf972
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:647a2312534d5e4ab5ed8c9fd7db73b14299542f26ebe0d09d9aa1ab8b93855b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ccfd649be26a017c1668e75beefb4a1a68a659e8305f3c899c6fee5d74d9808e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d45721b4400df10376a150c19b202dfbd8994505abcbcb4c1ed54e59552e201d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:013f014f506c90fd5d9044bafa9f144edef6edd54348af561d69bc359abe2815
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:b81032bb29eb6b81414794a172f055c6e0397af0c67f025a8b5f6303702960a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:284b4a298edafc7c9c32e66ff7d61e9a1d3f67293a5871654fa78a5924b7bb98
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a75a5e36f184cf38411e21446275d2e692551117ee873851e43579d970db41f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:8d5100225ccd1e99d5c0fec3e96aa61ecd3a0a02afb5ac7ef33648ff5294b2f6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d41da5fe1827da3f5f2b77f89d31b1788c9cf1b713f34e0f8873a5a4c21ce617
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c939fc4a02c3b74397908b8e1fe1425df4cae5d1cd3dc6e115bdda1b6d034e7c