Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:4c9741cffdae25d178e74dbaba927620be467165aff383fe0dca1146727ff348

Manifest digest:

sha256:071ff4680e99d4c0002e3ecf2f9bd4f2f88a7c8d1bb98e3a6fc00c0ec1aacd9d

Size

20.30 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ac4891cd612cd7672b573fc6bf203dc9faab072ac9c1c8fb5f51de77cd6ee0a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:82cd1c1dd05fae4e6cbbec74be6434f119c8aca55fba5b4920cdc18f5bd11320
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d624bd67e003f9f90788fac6ede3390305654aae8def1d7525385e084617e7a0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:60f465277004e6ef9367fef49d7d6b84eb9d797b5e780b6c062a304f27600ea5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5db2ad997975d539591f06ea3ac966f45f553c6ba62a60406c0d2567251b41b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a8bc2acc64309cc18f02bbc978fec2f5dcf105afaa381768d1862b889a350aa5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:be37b1b3efee173caabfdbf6b2d4b6ed1032f56bbc535e9aac175f06a4d67810
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9c41370badb8d790c4c281dbb36585079caf3f5e8270ffd778e73c03941ec10a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:fd79e8628c9186f94b470557f58ba2e7bd9c33f08734821eb1c4990be42d9f3b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:23ace73a73c32cb418f9cbc125f1478e887e43298caca495b8c855904d6ae0f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:dfa2a319be7d07717ad5fbb0dd5ee2be5791ba3228ac7fa96f4fb337d2dafa93
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:03767753354191f2ce489ada2472fdff49ff921e64a415266e2ee59d7185b1a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:993454aa8437f0eadd701e3def46375d8a663642b8a8578dadc91265287040f6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:eb8c91f033f964c7006cb99bb1875eb338055d4279c318351f64113574a046b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4a891b70df545c448c1d4f0998f2edf145b368a329926a01c6d3e8d5b24932a0