Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:df5ed42bc3aee99542192379ec0683d8296cfb1e3631e5e4547c0f9ed2d386c0

Manifest digest:

sha256:cc31afa66cff558d8663a806e8749cd95928ee0cb5aab2d4cb4eb583386b4ce8

Size

132.95 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d9898a580986db308cbfd72a7a10b16bea281d69526225ae5ec299693ea1c88b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1949b6144cac171461799b26e211d1624655252c6a69afaa5131c813e5cd64b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7306bc5fb9400ba5e07f50c0ba00b19f5d82d309e778a9f8cf984e40c9ed7f8e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b4e277c16717a4d8750d4ec5b4274bd47bc6af286dda07cec59eb4eaa007aa7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:1305d414a53df66d8a69864e06b45c08ad6455192a91a33379a1c3258c4f70aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1d0e62d5c92257eafa62fbc170d5d942ce4b5823d8cdef45ac9d7146eb28ea07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a717609c320d5322d08a3476b68fa07fed1736660de7d584777a8102ab9bf01a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6e0598a0b6232655ba7f6c0a91c64086bfead40fadf206b055037be94ee0afda
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4fb2fc19fbc712867aedb2f171a5393c17576daa41791b4d6cc436375d67fea6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:017f9ebb127427370d85751494583bd1693a66c22554ee379e379dd194d9ba0b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:dbafaed097d72fb67b72e22d21a00d083527ba742be075e2ddb40ca3ef10789d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:13dbdf716b006a218d52d762c131b9c6fbc24c717f8cad8877cee9c941326d95
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:46550a38a4096456ea672770dfcb9bba4a853bc9ab21ac7e2cade34b1d6d5935
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:87627ebe90299bc290e504007e2c0d726b1b87086730e468ade6e496af19a1c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c115ec05fc23755e69fb22e4c469c466d6a311864e6332b019f19d509830ceab