Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:86d02e5854ffd5ee6b110eb3e4cc03726f7657abdbf2419063f35f7dd0f104fc

Manifest digest:

sha256:1fe0a4fadaa2c0b5a4fa178d1f7191d176155559e2afa43caf74333757e99c04

Size

132.95 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:70a8f5977b36f7e9d3e98670bd1c34bfedfae52ef5365f1acd1a5a0e2e6c000d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d85509150fd75be083f84e305e4a29f72759c0a41cb52363895f22e392a3745e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:848f6ca376247a684e4796eedbb3a830b0916512dfe5776ebd7c75156a2be4bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:7bf75bb157dc3bf1b6081aa5726785d962f2e09ab17e3962e27a450de5668b0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:9cb2804af34dc396e3cf7748dbc43ca405b620c31c1ec0b20b97cfd8dfa6c92d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ad41bea999f806482628d428f9bb1edfc4ad66bf9ab7bb104a743b50c0c6a8e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:fb1c13ad34c05cf31e363ba979e6e8c5be21b71f7da31eb9a285188685e25c13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:caff6c3da7ed9e553368807f9e24d36bde91dfe4dc22bc33ab5f103da8c43aa3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:90e010e883b9c9a2f5182fd0c201d1da55934199b671ff278717e9bbb04af94d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:b6c885603d69fc33c1ca1a68d9d64e40a8b1a6acd7fa1a0497a7f7b063c4a0bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8339db9282dd3ab0c839efce7fa62e5f8e35485a3850d3ddbf1927473cb60aa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a985e90b7c8cf5a8c760ca01b904b1a1505b0d43f1f0d79fc2787d712b006d4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:46a4001ec60d96d61007ffadaf8a89094e548c77cc7d31fdc1e82eb609f42864
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:bafd83314508d62b55963e87db712d7d65d2565921484aa074be4a3aedf44fff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:84d6cdb503251bcdb9789b84e66fbbf9f0435b2b4beb8efeaa557c282816b183