Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:55066f2f1c8869b2af9547a0b6ee5819918adbcb671cfcd391588a82f2344dd9

Manifest digest:

sha256:278d66ba595afb4b3a368ebedc90f4c7d1f86540560cf8a0a849aab882fb3bad

Size

132.95 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:318d27c51a8c44caa02314892821f4fd18579c000e8090ad2ac02ce9a1ce02da
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ea0a56f0511154278834543f7b6ed46bdb35125758b2f5cbebf4a7d9504d8ee0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:9998c51349ac8876e6cb45f9cb2bbeb9a21ca07e7facc7c790a682c65b9c5b17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8342f462e20eb9849ce9d08b9af6075b0905783d4e211e3d25642d10d5d07a02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:07e892cbe58c10992ebf0c77eeb031302458fdd73bc19d16af6873535fef2696
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:52ef060547c17d1a256d3cc7ba3fe351c98e8e721e9693652711e6608f682f51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3c65dfe3d1e2f81134358e0f32056f7ff8d57692862c93f3f6e8e2375a175185
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ca74142b15f8d268954fecd31861fdec20c1059850369857adafd6c066489ba6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:318ea252303240d0b9204dbc0ec72702b6ecdfc358ddaac71dc31258e956f7f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:beec54007cd3c74a475f2dbc53088ad698b5867b5c4086bff89e18abb083d428
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:aece291de6d0a4f0456747da57720ffaabbed60df7f95c5792e11b779062789d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:eb331f31428e827df331ada027a108470a545085f8b267f6634d35b0539876a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d9122b092d394568e6d4551fa07ad354e8e4e8248e018aa53cf46413e22063eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2b0d0754a3c3cb0b6faec92b02844bf18ccb86c9a27785777621923a085660d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6b07613bc00f05a6a40b1249e831e819036f92a993d39009d94c0e56597111d6