Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:65204f3c5070cad2e085329f834b1140a32b6f5c25cd2ac4579119f2232d030a

Manifest digest:

sha256:c3d73fd982d600b79381f44b3b0f1d4f443044ea13943f0cf5f9721c1f04cbd1

Size

20.30 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:92aacb7b602763a0d38db5e8992d298f4730326ed0c38670589b70993f697f3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:2c8fd62fcad4475694b361882149a8a2da9f544e4b7c52a0da410211ab2f6908
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3e98bed735808ebd0121424082d1caf9c6bc57d16e2d1655e60486231bac735e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5eb37c6c65e703f656373d5d80589b7c572e392283d6f176cf76628caff81402
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:43cd461ea51e102b15e5fcb05158326dcb702dd7ccfd8b41df53c3213363b599
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9e3bfbe603cdc0fdb8bf035ff786a822f6fe4114b757b73f4c61e4f2a0ee96ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:291252f70177d32bf32fc4f1c9b8bd67b455bd8d00f6c6a5befba43856dd4ab5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:0d4ec46c6ac337dcf7ccd79abdc7013b71329751346976d00186fa175da981b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0e53c8d3a19de60a47f006ea35a49bda52578aee3d5a75cede2511cd656c5a1c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e9aaafa0a19161c019699b57ac30ea930378e521d72f6fac232438159fc1c01d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d792925f595f8bc7b8907c42e93c09b95ed9bd0cf703928ae2cc1723bee2a3e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:cb07d5c6683c1d4a2a8d462f7f11f67b3c52142d7d0c6cc90144fd56b3908e7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a05d8163fbbee9bcfa7afe2d4e657b18dfdc35fb85f6bb7530dd796419002dbf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:26b695d543c17b008bc4685fe7ef06d07bae78dd5ce923d28f94e5be532c7c43
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2450312f1cb363545ccf033207bff119e324b147c5071a400c67fc00a866e45e