Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.11-debian-dev, 3.4.11-debian13-dev, 3.4.11-dev

Index digest:

sha256:70703973d506a66d9d890d68fbece6259cd8920d49c9ab41ae0d1d8c0031d216

Manifest digest:

sha256:78059b7c64171a03241d88d9faa4fe33674554af4d1ad4b1fd9ca696d5d2c23a

Size

134.32 MB

Last pushed

1 day ago

Vulnerabilities

1
5
1
2
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:74fec06fa23e094f6885bb43769f9152bcc086c9b923918cf5d5882e22af8880
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:404e74772679957376640f744c33ed9ecd8fae6403cda47557a4e237f0d96eae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6813773c5933602fd832da7eae7ee4c124c85f29068c3383955b2cfbd5a78c03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e47929628be68c401f3da477c589ee16c2cacc18176f1c90b95210ccb0dbface
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:871eab7b0a27345eebf0d71eb1ba34f330d9c71760a260183e303552d010dc4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5909b679913e1d865a8fee90469b40b1d73670a4a5bd9664e454c3460d84f6f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:0e49df94b38c59492f43f6de1aff2ae9ccfcaa7f583ed1ebc1dd3dca9053a828
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:87b6b474fb3a0e34487b218c4c0db4f7b00dc2357c7e4b1dc20c787437bf207a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0c46c964b683412bfc41e7e304d61f6cac6b26b773961a4c11b97ba5ed298212
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:b1ff4bff9bae98f41b967da3746442e50cdd3bdf34ee41df54ba7819e333f600
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ac188df191e553f20d17e2f806bcb963581eed4e875d3fdff863dfad4dd13214
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:074dfb818559cd4735aed632453af53de5b49810c010fc70a22fc33e74a4b3e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1da5272dae8ee5339017424d676b17433f2f55c23e754f5a0b50a31e92d342cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:bba6a2b6206f3cc307e8c33d741bd3b3840c40eab55ce2bff6004d9d332b7e91
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:d89005592db96443c00b6cc357d28167220dd02effdbf7ad53c394f25a515675