Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.12, 3.3.12-debian, 3.3.12-debian13

Index digest:

sha256:c46f0fbfac6b8c48f5e609f61da90f4f8c1d746ad7d61694039c27099cd486bb

Manifest digest:

sha256:18e23ccf5c362f855d4e49383ac34dcd538c5480bf38f94a1d655b8fb77cf14d

Size

18.91 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1906ce88ad84dcef99407005bbec9476010691bef6aa5c499582df7d7fd17421
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:88a3e8e314ea7aa6e1884f3e3277d35497853b3d3095a0f5aa3594d0b65848b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:11730cbfbfc3c52b01a0a805e45740300cedd2db7e0e9c17eceb2291c6a34bd1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4bb41f551ce86a2c9d3b24959d2c33602fa30c2bf6a860fd78daab21b54f5622
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ee1d19f57ed571e4c680ba04cfcafe3297b590c37b29758f5cadef09f6fe800b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8de3080a5c95ed1c873f74200d3bddf391c174da7d66ebe47f146bda1cd6c79d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:085d3f898139189ab42562c2501ae1d269c8e7218048545e0a244e9df9a3b2a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:3e7e4e1e191072733af1b1a42fa0d9eecae8da3536034271238b43db090d47ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:de98024ad6f1338cd1d3951f3cbc771214d93dd1f1a8fff10584dcc1fa37506f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8d036fec4c81e6f4a6de45e354e590ed9af1c0f784f04bd85bf1eb4c4e683674
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ae98412054d8c1a544362a433263509ce997ca8099ec825d1d808be375d55256
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:79bd73f70991b6d8a10fc2e6c8a4b29ebcd8e63b145bade4e5d4f035246e3d3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e3ff4316b96fc1112704588b2000ab2ac2b403e1bb5091cebc48c2da14e286aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:5c6b795bfc89cd2d4c423829e24d801d383c0d09052b15b58fd684d3a7f7ab61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:d4922ab750321d49bd41310ef114da7078f01e40746568056b479f635f42b935