Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:dc2740b2ee41422ca1cb0e13be6f48bd8d92dfbdf1c0583d72233c5122c41b08

Manifest digest:

sha256:585793ea6caa7660d44793d97f1a55e6740dff94d2eb6d34fdb07189e98b6382

Size

132.95 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0f73dfadde94b569980e9316204b6c8c6267f2dbb63d4f2787fdf01eae186a6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:48d24e1de5e08f55fdbdfd4329bcb77bee6bb8e23f7b9b6b17f3c57148ee7a16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:665ec271468241a9f46309c8c3fa65e849522a0cfb207bb0498d4d3a6fbc7cd1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9a36440317ac27ec4cd4cc58dd2a310b0d262f5f07ffb8d3e6c1d813fe063477
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ca3d92c8f7d9d1c6b79edb99f297287906e855b350c53a5e9482e3a6f0fa24d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c7a178b9a7cbf7db9e327f782a463c8b3d143f49b403586b1a5c45275bc66020
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:76e74a9aeb811d291b886a498992a30819d3a1e61be5dbe0e39eb4af55f75650
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:3223ec481809d74a17da06f4364ac616f1d1330b30c7d2d52639c9c9fb16dcac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e0d775c4225a34d81ff17d9963a5702eeede7d9640d3108cf60bf7e24cf08a80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:38e4f6fe48285f4bef1b48ece46a29cde854ffac3837a49d803cdd7c8f055e83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2ea2437d71b19135047c84cd56fa8ae15c8a6c2fca84aded6b8d39bf8f74983d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7d21c551df3adbf3849fd6e1f117fac6ac106f38bfceb58e029d7b3d4c08cd35
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:64db993db5939d3149ac42aac9e8049e21b54679d42fd9ec20ef6586346d4a2f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2ab53c797036f91166f911afb80295829275f187bec86f285e3efdd8a6f2ca5b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b70657ee4d4451cb3663d7a2d3133d33ffc7a77472c22a96d8ddb0ace30d95c0