Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:6d6b5781e2e6b0797429dacc5db4194d2934098447aa2b0dcc890dfba7c0693d

Manifest digest:

sha256:eebe9f4d1b94c64ec5a5ed8cea468071a31f0ea581ccbf2fb456017da3e548f6

Size

134.34 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:da000015ac318bcbbf3d504f1e292b8ff51290dcbde3327b8d61750c2f3571d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:786acd572d15854474e6c6f3d077c681d5fda618cf1cd56175f844bedbea91e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:952a747d05af37eff9b86ec91c0bc0c764e0a337b8ee6806fbae44d00463254d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:249fb29f0bad9a631dfbf6cb7755ad47ebe6338c1491bc575de27ef6229a5fe3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:3296a3a26bf6b5f58de1ef40dc6c01a4aaee4d191fad3bf7d692d5d42e6c58c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5df41571ca0b28e7102036fa06d1ead0a62d1f4d38886ceb146e7c50f9d7ee4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:2db4ce26b0fc8ad7610fb888a6cc689a9a1ebf883ed0c7bfce0f4bc86f440ab9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:caa6a83ea3a96c1f2d29d4d4ca195bb24da3738bb40f630153c00a8cc4051bdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:9a539fd89148f7ff520f2f77808eb3d2bac4f858d2d52a053f44c43ad55b96d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:fbbeb435d531ffc33e514d8c99128e6cc205029aa47009347a5fe717f70c1127
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1222a74862af6755d9fb45434d876729ca32884841ae3ba61a38095814132c78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e85ef0605328ed06e709421c769b317e6373a564aef952b4b437a950eaaa36aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:23f6db4198b2043eb42d39f3aee8d96c7d50e91bec27782378c2c74527b11593
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2c0c88bfac6e475640723519df053b046e363247c2e4a9a4fc5fdcd6c457cc6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:273e90f5f418b56278f24b02543a4033f1ecacc01d879c47ed0d932305062254