Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.4-alpine-dev, 3.4-alpine3.24-dev, 3.4.10-alpine-dev, 3.4.10-alpine3.24-dev

Index digest:

sha256:30650b5bc15c0ed1ec2678e6f24a2a9a5354438a0dc7e40f91b065b83cb4c282

Manifest digest:

sha256:943679e3d096be58057c1b5b98442b8ce538c1f417f2987815e41fd284813277

Size

92.93 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
1
2
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:939d2567769821429c610af7d3f6139ee22b05d72e31ce420b3887c2cee5c0e3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:71f3ae5aab375a66f9545fe32710ee1922f75cb2c320fe74f0c8f9cff00e5429
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4b07d00762712be4a4d218ab60d5fb492b65c991a0b3ffc3456d7f27f984afc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1eeb744cd9df97c5d975e4299b627846b293c8b3770dc56f2717f50189c05b3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f766bcd226bf418ef2a10ae9a8571ec7178e4b661583d2c101e7919d782fa90a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d9c20c873d29ae45bafb8e7173fbf3a00c8332e8ad25c8d553cd934bfed4d336
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7101ef6766fafb7c9ce257bc37013bc7ff88dad7674ffc95be9c118529bdcbdf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b273ba6f8da4efbd436f15e5091a8eb2725157d8ffa0ac9eac8a78a6c1ddec96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:4702e9cd1e50d7400a49b736a5d5e1861b7921e5a4dbe1136f9bba1b3c836383
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:fe1f81d395c6fa31ef242d2f9596849bffd564e7f90f26bb85018fede1bf75cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:bb1129e5f37eb81ec0375574906028529540814e3a9bb542ff125886392c0ac8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:84b275bff07f77a0617aafa99773b71ba3bc641b5cbdb7e4ca0882e36e33b87e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e73c017bb03cf9c060c005a1558db4655d0d0676372a6ae729ecf079b043556e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c0d85d91770b5cacf7d8fa813d3bbc02d6826505b5d45e12d983a2c09873d5c4