Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:9244353bb05153f1cd38371ec63fa24fb6fbf80abe11de0b08dbb4079b6e233e

Manifest digest:

sha256:9da97a0104311311f98d39f1f4528ba4f8ec638e8c69942cb4b6b9be33187abd

Size

134.28 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
3
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:882f0fb010883f903dceb5e01ca1f99de1515d11785fe9dec1d92bacf2c631d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a2656ddd30b67e5ec32c68840122f9847bfe71fc5d05af26582e5819eee58ff8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c3ceab41cae24a1361a638176a86518922724d3033fd38fc25f8d754f778ec7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:59a83e37cbeaf426b2fb1152a4333b4165670314255fdc95c3c3d14da571d6aa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:60c601d4e28914cf3e635e8dbbce88f8d9d1f8f51741126c313f3303a820ffe2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:33b7fddee2d44eee2eebb23781f0e5fece58d632813706e3ba09d9bdbadf9196
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a37c6738e2efea311e9ccc1a4ae7ca9532ef0a2f97e451c381582f50c25323e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2d740d45db6cb8b408b51518d8532ad8b99e917b8bed871234faeb53e8de6eb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:eaab6f14c3685f6a095318c05c21a93a5441d80ad8266665fe5afbe47e701cae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9eb4493503ba84962824e36ff1028159fa6cb30decd0b83afb5191abba26c706
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:94bc465fe8cda31997f7d3e84013df0e82710844781d3d4b5c7e70d4301ca9e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:348c1b7d11481a1a9ec08dd704d416ce4359cf35439e36967d2926ead858b816
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7ee324093397223ffe0b88427af066b5669cf00eed733fd027628abd7846f00a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c075c27037a2f42fa666733d5b2a4f9d6546ff52b374fd032344da22e7224b5a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:63fa943a501d701962b352dd3f3e6b30bfabb0e67ced0aaec837c540f8bb3fda