Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:73c05358ff8b6a7d2a36c9b297e3b261fe180a2bcb311e7923020e4303e9817f

Manifest digest:

sha256:bb1ea6a2baac8422616e0f7ae3f08ac9a676d0f250be3ee22fdc0b1900a3ff13

Size

20.30 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1385654ca3a0536081989af3c54603b7ab53c3ceeb14ace55830d7713821b8b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c23a16272dffbf125b0ee624ee772be9af91906962fcc7480e3637bea75795af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5a3e0f2735c4ad6989b4cbfcec3bc5507398dfb4d8b592f49c80a58135df30c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6796bb559698da3c5e18f592f505668ef0b4e300d7a84d95eaa4dc8a8aeb5889
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:9253cad47d77908c843d272c1bd669d294d5cf28e53bb815cdb23e3a1db7b5a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ae3b1356db60b0e930f325adcbb995fcc8348bf275678e6b7c991914b298766c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:13e526b36094c111744647c90742ec139f5c451623f1954952819cbf08ce417d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:31226cda786c1f60527efad9e887f6102f737f6c712da6bb7e95d6b850c6f6f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:518976603159e1eb685d82dd806f83e02937cce0fad92f0c2c8785fe8c5363a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:041fdfe4bcb2c010c6b6b5967bc1a3149344d20d3cd099fb63a28c58e8c5d00e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6a1d03b993dc52d17b434eb4935d894af50cf370c7ac5fe986f32be773241fb6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8155e9141520f81d785b5e35d75604a5a0b510ef65d0f42b3a2a7ed411ef4b25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:80c200e15c8fe49cd68499826ab8f9ee0a9900778cfab7817006a06ff71eb58e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e03230ae2b69abd2c9018f0e41e606c74bef23b34021194d3cd76c3738d0c137
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b862f59f3b7dd2ec69d42459b54ece1fdda035e7df37b720e357705074c7b54d