Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:76c40036405278da4e7c0b9e4837e4956ea10bc91b7956e94a667dfb0114d234

Manifest digest:

sha256:a3a5cf1f7d1f8a85e0a4e2a137f41e50e24d232872676c253e0eace486fb4b00

Size

20.30 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2ed3f223a1bb67f94d25bed9772162b5731b4ab9dd8a6b74f207938b0ba52643
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a5a9ebbd012a27369034cae43327d3ad1f7d44949ad5f69c74d1b8e4c5466afb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7e754f504eb62333ad7c122dd490b77b3a569b1810e505da369ae04e4af26605
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4607d28939e815d69967a3d1abdb9520da51653dea79a70dc351b89ab9150a81
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:32c46bd206bd58ca622a1aa33603c8cc3a43fe674806629c0e31e62320e1648e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c9342dd4b50906b9d9238e5c91a3f5459add82358f634ed3fd34e0dcf39f3bd6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:6f7a82bf1220ddf41e8e5f1402ee51b3e4293b1c0a14bf33fcd209a1b833fb4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c0f4ac60f25c1258b51a99b295410eea43dcb3ccdd533e5e7fd405d5bbf65e98
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2bf3f738d26924ed0bd1fa6d94d78c729fbb50ab36bce61f8dbb1b6a65129236
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9d8d7463854110ac7404a5929e8da0fa94fb82abf564899117796573ec721599
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2f0ccc1e3a53e0143c729987ab0d372bc123a1e01313882b1227225b3ccffabe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c6d245814eb6cc58584ab5048bae778c9505ae18983ab81c65d90f69895f6c09
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:6b1ffb19464d5b1e451cf1c802816333e33e48c771540ba1c24972f954a76fe2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:9f0385ad520fe62cb040680b287e2e335ac2bd5dc4cf733d40bd04b5a849c747
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ac08c4568ef16bcdb7aac679ebcee2a25fb26b3de9c5a350bc2e397c3b5f16d6