Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:3494e2b97335ee032490c541aafad12866cdb4a8de378d4ec53c0ee073c3ec6a

Manifest digest:

sha256:63026b508751dd21f70c81c38a4e3e0f2ee64c9a9c108ad0d50fb397cc775469

Size

20.30 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:be863c804be7aa3d1f70aef390fba8aecd11fb86b9912f34f68782affe1617cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:aa206073dafe6fc1d67744c3c5c2fa9f6bf2cf0525a7222795f11a54e493c2c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:064213f88e6adfe952c5494c5b37b3a25587ddff07d9744058d7ec22b837ff5b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e97f63b8bf7c5c0917792c7218c2ccf040a76f231e569c7ab04836c626574beb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a96265fdbf743cbc5798fbf065d2f02c68b7a839c5822c6464ec9ff43838e029
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8a73d9388030e54dc0e34ca245aad65e500b44e374c0e4c902fa6bc1d7a35cb9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:0e0915fc5736cb215d6a124f31d7aa597b23433f38daf66e60aa688163c24764
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:06d61e3507d79e7ae1e40dd169868aa94fc4d9ea2e8eca5dd84dc2be10c6a431
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:06f7441f4720e4bf4c7489efb145fdaa6d0f9766996ce38b9de943e749382500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5496759bee07ed9eaf8c0130946f0107c5bb5f4c92aa7a464189123423219ce4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e0e343c885641537f4889f17d0b82b2daa346dc24ad9ef68d7ad732ceb15ca36
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:389a01f5404cb10f60e6a91ffd92f732cdedc11a81872a74eded6694aa58b234
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:812ea820d24521d80645312d7530779951e13d7ef8d76af0485eede6566006fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d3389b0f9d1c6c261d0aa2b5272bb087833b1de04d26436518b90265b7e76077
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:30776953b41fe84133b5529e463c994b40c5d069806ba371486955587fe963fc