Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:f857e1a4a2aa690dce0ae678c24053961f99828b3dfdc84e28fe6ac0b222ebef

Manifest digest:

sha256:a04f2241a23284e959e058a248786b3014e9a17d3c21ff9a30dd1b0ac27efd35

Size

132.95 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0e4d5e33b5087290ea05759d9b0bdbc3547d152b96c61149af0e2867108621fe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:45261c6a848e0ad205b9a372189d54d2225d6e3d920379dbe111accdc5ddb990
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:90291fc5beb619671e29507e2294593b6cfab3a970b09e6f81e02122c37f4945
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4dea9cfc273133b16e4d55d99e35eae92864af61b9ef99d0ec04d002c24829a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:afb742c26bfaf6bcad1caa1ad7647c406852704c9adba78caa8d9081e9b65a54
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:bc1a2537d3c3b4a699e0150dc048bc52723fd0ff0e2267ad26176855b4312ddf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:fd8c77574312ef069c294ca5ef600091f44cf260a904ca3d6e4085f865249949
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:75c8f3f2633b9f3926c79dfc17a3ce006e11dffc9fe3c3c711d6848c560e9e93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:96a430943fd3d1297ecdb12865b8095bca3b9db99e496d27695d93ab85476e8c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c3d821e039526778d4fc54a083690c00a0a76e892d51b2cb23203b845a766f13
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:f5b0b66f74cb2a43a47c5cee818b99921b3d88756b3328cd04d36412e261a266
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1fb53f6faf4903ab002edbc5b580c088d37f64799a82588b31661b5c31936a57
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0371daa7ba38f7d7c4ab9bb1234ef00e711d444e991b26e059346f90f1b1ec94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:38be7466a1324e225a8f215b706d6d64b058dd84ea898db4442750cdfc26c97c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:0ac4389178b5c532208950ff86ed72c8019bbc95d5f9c6bccfc1d7775bea1294