Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.11, 3.4.11-debian, 3.4.11-debian13

Index digest:

sha256:8327cbfed677beb484a44f316465d9563d6406ed0f1259fb84ffffdb60fde240

Manifest digest:

sha256:e5bd6c58dc06aeb13ba1f83625e01a24b54301cc82a3ee57e7795dbec179e4ce

Size

20.30 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:779c187094af039bbd89df39caabbe13f8d8a7a73992cd7cc177ed2c326b3e4a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c68059f1ff3e2b5c696821850d45857d5b951fb1789290686b5995cd9254bf23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:dbc61dec0bcfa486fd78bed42039a08fea3ca082ffa850ea29d785e6487f2252
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fa44e33fc21c31cc205525a49a9d3ea9c8955f6c57bea6c4098d590dc59cc646
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:47f1a98a215d3c76ccc5d18b81420af21abb81fb9ccd1de63d421ab33c6f47af
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:299138c37e023392bcdf194a0077b5e5dbf22b61aa2db21b97c7811141568d8f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:913059b3925ffc477b983f783aedecefaca10adcae2c460da8df1846fc920eb9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:03e1f7bef72f42e67a0d8c16f2ebd2d1590e616e222281ca2f5065a4077090b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:9df1ab198d3a0323eddee9b917fbd1926bf002e72b4b50f4d9e76cb329f8f6bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:68f9edfdcd24de29dd41acfbed79febace17f466355bd40e1b3ad67376dcf90b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bb886805c70c410983222607db2493c2aad4332afbf01b3c50c4e891b65ef7b5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4c115e318e2e799a10d957028df19d2c330e5fc81d1405fd0b8f4d1baaa7c2c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:fb0fc050dd1456666086a0f2514f265362d521c76b211c2d2e85c528b5c93cd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0832e12e8f0b8db0e95168b6c1911ce9fd26a16810f31a5643e6bb55b146a701
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:0ba182905245014a04fb75a52244700122a564dd5191a9932549f7aa2aa9535f