Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:4977fb33722f562053ba791ed4b8b4ab4b2bda33a9f89e7a386ec09b7c1129dd

Manifest digest:

sha256:e7edf22eecd074bd716f20a0122aaf86fab9d40a0e9daef5359ca994f82c7402

Size

134.33 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1f49dc850d971c0322d443de0d42eac6baf88f4e78fbd1117149b5849fa93edd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:71fd5bc2bf250257406ce92ba267d0cb844b06fd0d0799753bc013027fe5dc16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:013f23c93ef11da841971282d9461d851215dbcbbd816246b704d41acb0989e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f5c7af2c8625578f40a55a71c2b62d744220c48a994934836a913bd7a2f9a5a8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ac49797b285f84e817b0117196750cf3972ada22fe683ed2c734c55a57057bb6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:65cd3a3f9090d51752742e4beaca059ffb3799c47db316a09fc42e466ed6ef1c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:32c70ff8f7c4e3186001c863282fc8b7bfc98633b6cd0daf935775c102cec37a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:258058b14225f56007861a632e285e837b9d2a54600cdfd1a66f45b517d87750
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1c546ae0dcbd73b5658701dd6c59e897f571d65367266beef4d8595cea2bd7a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:65c8fec0b5d2cb011bd325d546bb439e5145d0e909aa3f366b349b60f5eddcd8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8db58e37620bbd9a6b08174ed336a8fdca4bba750230393da4ed265c8733bcdd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:65dba87ebc070c184a04a40cdea2ca2047416a46aa7d2e059555190582d42a54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:32b67e9f5d1d975c3cfcc1dbcc04e7d81db6164646be91436ac5173f03a82d4b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:808c1e802863382523487e3c993ef599dfbb7a283944f9f4a3192bc37dd3734d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6bbe686f140e95e15e59849aea045ea3b66fc90bb7d168ec9d28dfd23292cc32