Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:5e27915521da411534470785fc76e5ecd2b21a9db25e8ab96cf20da231b746ce

Manifest digest:

sha256:0133e57dd026b7e4c3e3d37e26e362575de9a1cc4497f168a5d244def87a031d

Size

20.30 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5c60d6dbd8be476d7db9da9b39f29f245f826427b37a2e7c806c81a1db0c8b77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:889d51d47ffb386afd3fb7c64da45830f2d853d099d7226c322ff8bf7ef0fb33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f7ea80a7c42fa7c6ef6da49b94dba6e11b985fc010a6b615b0e69caf70c04b2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e130d1de6ad6d39888b45f392fcbdb3d7ec4df34ff4582baf488809763d160bd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:82d5ac9b73c93a918fd20ad91c86540434b931940403bcc7135b59ede87570f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c4b30663d6f35bfd6f1ebda62f45772e3aa42d707a8e5a9da60e5e48bfdc3f1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d20f25b220c9a69457e7b12646f2da3ffb4dc47f9135de13ccdc19750939af33
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a52908e3d8846c491ed3b598f0b9f9aab86f40584051e2e5bf7d8c0822648036
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:cab4ecce9d9d8d98e9e114b8936cc7cbd500fc860f356d96345c5ef6dca22966
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3082e337de7f470bb1be97b499be9940941bc3f7aa8c9d2bd30230167e7e1b4e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:90950f728603ac4f118799b224a9bc2e09e1228afffeededf3623cc51b2fd20d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7f50086245170ce99dff951c8b5d7abc88e00f3856894b55675c2cb398f18522
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:446d8284c6b0f25384904bc864e2c10189f18aa95ead35bac0683cd1ba75e717
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0adf1454a001bd82c672639c8003ccfbc8e1ce571d33a4ed79614e5d6eed4340
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:74ed05c6708da4a68d14ef0e07a50d67889a4790c42d5cfba95d018f6d8239b0