Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:c9e195386a165f6cbb632070507844938373b3aa5eb569e75250e78357984327

Manifest digest:

sha256:f81a5155cc3b4d502f3d6843ee51659abca1d596d7ccf29ed85c34b52d3c3330

Size

134.32 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8763c0dd4dfa9a684a1378897bbea29b218cec333beb989c3222700f6de84ef1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9dd1bc40b3599d2d14671053d839d44aa91b19c0d4fe6920798e03d454a2434f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d77d83dbf4771bad1edb3e5f2166f3e58b5bc9f327e3d5bb3b0531def5ac7634
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d567656d0dbff75a1a40661bb538d75c41640188c347668a242647e47f6d7cff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:bbb5d6e0ef9414b0f0df41400d37106664e623eef94e960939c563d1ded1e566
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:84c1b5cec35824f01aad904303fa5c1d49dad50217e5bc303555a038e4a9e9e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:647e56c769a9ecb00a0249b770d3fd8274c69c4774052232b0a001b05fa50d74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:23cf1fa073b71ea38fd044cc9a834d77d227ccfaa53a038cbe54134158ec44a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1dc41f0a614df3978c4cba4bff23303b162e33ba40839709e6224f2aee14f50f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f8f05e9bf83434c79c17e64353db09e387127450c080d91ec2fefa18c9dfc379
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:a611dea1e43cbda800ae2b97c0ec3f789438efcbf42a253b9dd969f07ca6ccf2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d41206728b821779762a974f468d50677ee79915ad2fc649d239fd44a85a3ffb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:057a447ada4debd214b5a0e4d99991e18b838994de7cf4967cb821ae00a39d5e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:03dc9e4c20a01540fb99d5ab0edafd964c021f8fc617efef70acc7f7b1448262
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2fa096d521e80742c95ead78abf54b414fa2aed7e257f5c43b056e46a816ffea