Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.11-debian-dev, 3.4.11-debian13-dev, 3.4.11-dev

Index digest:

sha256:db4841d2e261f3e8fb98666372e71b311226bb03b64f76df2f3ab9881223f728

Manifest digest:

sha256:98c5adff1773d1323db11f9df6ac4f1a0f6119bb86c187be4437830a3c8a1ce2

Size

134.32 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2a077a6ba6dbaf89907f6a1819ff12a6d20f1ba4a284f6f8be3bc57c8dd99ded
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3e004e1ad025a96a142fa892bb6927014ce625510ae95646fca0e2b748c1a0eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2d759dca3df71412c464a370e3380f547fc78b440d43def4100363cd63a360d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1a16268b900849a3ebb4d0fb2094e105132cda3664d9dc3b1043993f305a6fe7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:581395094b5b8b4dc14eab850955cebabd70d70b97371e83cfbdd4a9e41f173a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:861036d1c80db22ca0bf3cdaa11ef847f5db7999c66bc0dec2bc025dd4a07662
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:de8ae26d24c8da1053299841097549cb1ca08eb2a3ba0f351c869a50b24f0821
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2e07220663b13d0b8444225bc46d130dc6862653601d45ecd39320c5ae54f55e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:fb1782c58e54741fde10ba3aeeda324ee83b82e1f5bc32947b968ffb22e74eb9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e385ac8687f859c606a7c47144fc0a0134daccd25d07a9395e7d6496f83ecd4c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5fcb5895711e8eac8f0e292865c0a33ba85edf14471aeb1b0749e46602843ca5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8ee8a31d49477a11e58e688f62a5656b99e5538662ed523acfb13252e30d0490
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:549e3947df51a2d130436424aedafceca74d65bdbbd975e985c03a8eeb46ce06
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:97a7d57b65a51e70eb1d36c07d46b8a6f53a81f3c423d6acc2801256cf5c869a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:3b59661b0d2ee2ae8561ece783366dac4f11f0b64ddcac3b44ea13e6bc690231