Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:73829911a9a3919971668b2aa68542737c55ebdcee7f921bca98fe5ea8d6e8cc

Manifest digest:

sha256:da43e6d820663406c0d55e78dd50baed7acd57293aa2c648235b8a66a4b1d322

Size

20.30 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4bc15a72f9ad3a7dddfb235ef007bd1c961cc4016829c8dee125f7ae82bc49b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8106f6f901f060fa55449de896e9bb5fd8c3f4e2234bb5e79d9722fd76ee2f9e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:95dfcedb373988433d82a1e97dd8e40aabf79f4274879299ee0f76b86aed6590
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f2a0fdf3f4eb1b0c685613acff474af3f76149f6cb13b7069327a61016195f35
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:7448fd472930651fc3305209cc4b936a99c2b50b61a2ad1fc67ca11c32394ddd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:e81ab975dcb7c9e8ed244358dcdb19115c3d018347ef322019ee9ecde00d74e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4b750e237527ee1e489d9f8b72fa5bb30855b0007d908b8188c15938c8fb1887
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a1a1a1fffe8b3ee76f0436921d3f74a4227f74e804ee6df949de8ad5c90268be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1b93a7d6717b7c4e4afce0e8326cd63794a8198c1ed0532bba70549e36bd0e29
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:de7e637ae674dffbbc5f8c30835f49d39e2a221fcee00af6520b9417d9329d6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:198c3cdc5edf6352a5163f0c8194325c9d52b02b916e9bc3a30e03fec2d6ba0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:490afad66635d8a3c8ef81e21c73b42bc9b1d3716f98ff7ca0c18172b76a8c8c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:29d58f2de8ff83eb8e944e66202ae62dbe0547e0caa3ab8c6ee97f8afe842b64
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:13f01199c8787adfd8b99768b5f6da1482e389369c92717454b658b8730608b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4cbe1d7dc2f91ea18d75a2dffe38744dd4f8672f866dea25bfffb9be0e25e820