Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.11-debian-dev, 3.4.11-debian13-dev, 3.4.11-dev

Index digest:

sha256:6190ff4ab83914e345328b1b4063abebd8af3fa56dcb3ec7751f731c95fe6eb1

Manifest digest:

sha256:c1f097506e87308393dd52caf512fe890c2e0f2ba4a02cad21010b3c53075468

Size

134.32 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a41f35e4ca3aac6a1f21275c3a9250fb6216d0af822eeec965f9b44edc9a6407
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b9cb660be89b34f7651dd736e0f2b7e546ac86568823fda1bf1222ad5f8791b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7d2f882174c905339d46aba427c604c080c2874e7488e6d54213b3d8fe5520d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:13c3cef0077c84fd23249e96acb84c09ee5fa583c8afecd2de421b93399839cb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:62a51f6d17b92f92680600ac32356db67a5e8f37a7b7ffd6808cc0d3fe17e4df
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1c447df0602567edb10a72c772b149ae9608095e56f02abc93bcf5432e0c1d77
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:862ae45dbb4be10521a73f5654a989ef7eba41ad76224174c22996d48bd0beed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9f9ebf81161726acba5394f3e7104f7c242cdfeb58042e197bad63cdf2993509
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2b5fa89b2df8e3cd4db33a78caab339b3655f55d142ce9a0e047c2ddbe9e0c84
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:58fa3f2cbb5594aee036748115bb08a8a64e05f1cf0059a2feb3763fa3802b74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:7b6a67f050ec630c4293f5ff6528c76d7aef7246350599eb0d08c0ab820b13ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:71503f16d0dcf4eebb853cce63314f794789e0febd3b0663e207d69c0eada1b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:458150678701cb90ee0366bd23171d9f7eb9e9adbc19a74a058902fcca85878d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d6a28aa0e951510913667ce37af0eb2e4a1952ff1b02e0c476de039fc8c7338f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:47f8157c47b12daa77bc4707a8ec2acb6ea6c064b831a43c080d8d36dd939a7d