Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:fd103ef6a73b6811495d9412291387b09fbc7235b99720fdd85c67c2ef5930e7

Manifest digest:

sha256:c6f55bd52a9b2ba7f54aca6fbd0276eefb9ef360231c5b738de0b670fd5977db

Size

20.30 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:65b88466ab81a9d86c041fd5c8a2893dc4568e40e7fc68af036cf8c4eb5e359e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:230a79b69899621344acd1041bb3e4f884f52445ad194e9d9b68d6ca46431777
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:15b855c123d52e0438d9b6e79f86c25e8da914e4c3ddcff9409d6cdd5845d6a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fcf84cbad1e4c9ebb6609f593a88b6797d947fdebe7edf7b2aa599fdc1a788e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:bbe1e95a16fbabdb329111e8c6480262fd92686e53cc38ca17a1cca3b17fa403
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:14845c28647b8d4d0b8b5cd7512daa647f04f328d3a5acdebc9e97f10a0cad59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:35343be3d5609862f4edb75871ccb335b2bdf111c2a32d84c216a73f49c2b8b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:94fa6ea174b2539721863b8821a179a07618e346021e0f8dc9ca0e47919da08a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:07fd6921e4b3e5fca703acc0f455e74f30eba944fdf3248fa8df6c546be3f70d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3d8964ccac4c01864fe4fe2cb5f5220d89e4884a29e4c494e93a7bbbda9e8091
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d3e5ae29820cb593e6a42596cf5403f01b71a7b19235eb4965a5118e249b5b60
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b93e3fb0d62bbe30dd15eb6bcc673dda12ea08ac2fd31af622eb232fb4452429
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:bb90aa213d8b1b4aab57a2550133d11c920f59014017e81dc9bee58968bfba62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e7e5fbc0f151d87d2de2736c97b8f049c50b96b6c13fb3ee3635883353e649ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:a5ab63da75e0e7a484dfccae6545eb02d44e702ef73052daba846fbb1053f05e