Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.12, 3.3.12-debian, 3.3.12-debian13

Index digest:

sha256:903f07707d43d41513bd4998563a7a3a5c7f7c529a60138636486367dd7be3ce

Manifest digest:

sha256:3242d0eb5c98aca13d3b411a3d4932e75b9a47b1caccdb58a8fdc1f0413a6643

Size

18.91 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8d245254be5f5f8913f07200437db8a5cab78f4f696d1f26fc15d2bacc29d9d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:387e2744b7edea9b6f5dc812d5ffacecb63c4dd8461df12be648251f14c3ace1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f7065db246de19cd7d21db5c16bb9d87e86d2be7f9190af19023295c177bfb66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:72a3f1838379abf7715d89903b7b79741f4d8f0c96aafc43c82408b465588876
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:29e53debb536e20999df79cd8918ec6c1018fec26dcaf2ca0086651ad4db0ca7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1d87f027dd5495196224eda2162ce21caa7dc12aa6e3e0b05a069ae4df137424
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:43a95bd7605f30073dc42a10cef649f7135e46b74e4a0181f86b9e0d29c92f1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:56b17b32d6933807263349fb6b4ce755264b6de61dc33b58dab2176890b1ae4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:033fbd6ba735cb3ce54d780f2c9ac88798edfb32f706ca8eacebb709c8881aef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:472be3d79af55ca63a912f496aba10894a3e1899d3dff67aa0777c4b57881e88
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:93903af7d3ec2dcc1544430a3fece301c87b5aa1d6837c6696386c3ebf86ce05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e2dde8c65b4b590686fad73d569ec56c00ca4733e415618f3ed2e5acc32ccae7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:cabd31323e5b6560962c7ed6eb3d9b2981cd5104978abcfebfbdc95cd7d370d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f70c99f8f275322f807537ce2d66da3dd605b296a83e719ee1f594fa53361552
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:42bed6806649dee1bc629c04afd3094c0cc46c3fdfe3b372783f06649232284e