Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.11-debian-dev, 3.4.11-debian13-dev, 3.4.11-dev

Index digest:

sha256:d8ea77db71cf95caa0044fd7d7ca6a7c5437b0b0a8822bca51ebfa412e2e6a9e

Manifest digest:

sha256:be9ef8e9bb76a07ff758f2b8c3255b4e1ffb0320cf39b16d148d73f67a69dae9

Size

134.33 MB

Last pushed

10 hours ago

Vulnerabilities

2
4
0
2
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:231e34f81ec37bb2ed472cde3ca6f691c6c1f6bef71f5bdf2c7c3367812fc770
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f0e8bf5da36140674db0322e33e43e868dcdbc4010b4ba32509a4646cea5379a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b2e12ff1c076f1cd110f6832427f0b95124c9c1175cbc0ed72c71545c6721a2c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:039ba3cca5c1c49e4cf48da2a04f6a18c6c9b04a06e03a6687eb19e4e09252ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:21a9dc01e006a88f715e077bff3287c23884c09db17b1983a7d93178c5280457
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3c545ea0c32ec83d1db2feafcc67698f815acc5395bdfb84cd134353dde0df08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f794b711f68cab38c4379973054ae94a31b0d9d2d961f7744acad8252eb0b98a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6f95f651cb830f85eeb67131aaffeb6d7a68323b73def2ff8e0b75bcc12d4a8c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:aebc5e47c9779e07ffbb1f9f36bd0342f5f55c632b6c91ff898b6002b2f39468
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:2b13bcb99c619670fcf2ab47a795b438a29131ac4612643eb8b7112b2d7d2bbd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:670e21e24331343441383b8af47c44a92c7c54bc7a567f8841509e3f09c391b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2e1a5f2f167a547d32d3c864cd3f85bc62ae6e1856317d67deb181cbb8f04271
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:8714b3690fb5b68b0f2757947c136a1161518d295337cd760f86e9d60dea1f24
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:921dbed9c00e02c71dbec7cf88be0a5848ac27302f32fad6de26e892d9abb020
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:a9586ae4c2a9eefbb25f7b8972c305f29042509ca55c1bc077f34a28c0acad74