Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:62683bf62e62c49d3303dc1840318d5006777383d56fd839a69a451141a9d0fb

Manifest digest:

sha256:ee952392555e2f4cf5f08eae33a98bcc26779dfd7ff292f4deafda8b779db9c3

Size

20.30 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1b62ebc22544ef2077e55205b7faa6ea8269a85e476209a85efc3ef86b592de1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ae7593ede1fe6b60cfd620472004cb998d0fe18f0587fc6fca72ac40d1f8f70e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a8f3ecb3802225fc4daf17f3df1d2319bd9736f2a5ed2fb584fb391ac534dec5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:733b5cb47cbd7657dafdf884cc32f3b397e8469c3032572e160ba1a0af5ea027
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:fd51b45ae71ec98ae16827abaddf1c3ac87b4678cf63b8e500d258d0e1d302a7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:25eb09559d76da1cc06dfb3fd08ab8bf1d3e129c9f0ae13275a09b490803127c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5451cb309562212f99c7634524d8792fc4831761566e3d219b092c661a2ac48d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1ab13c1868af0b418e634b93834e515536c4a88f491976ee03b2785b11cffdf6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:dba212d03e9b93da61373ec73c85f17a9a166e36f78a58b7b0b6a6790eb7bdaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:af5d10c2e3a7e4fcd4d2868245de203ed72eae1c547645339212c28516166103
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8d1610c6c82be6753e2b08bf385f4d6b162e9bf3d7929f76fde74164c3f990d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:77f9347c30c42ca70c96d06899a274a26b8fa1df6abecea9f2c62ceb8df6e6b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f346417f5e5549c88f407016908fc598f8e922d6906bed08234564299fa5a849
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0095db66b5254f7644b9ee8233bb513772e168e33f275c0f553f3baa9d47a308
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:d64ed5d30704d7d7860c3776695dcb257f76f2c44eaba917b7cfff74bc5610ba