Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.12, 3.3.12-debian, 3.3.12-debian13

Index digest:

sha256:cf325b96d2a6cba46f47117d8c49d5b31268ac19037616519f3bca917dfa65fd

Manifest digest:

sha256:dcbeb4655c8a4b0d84ef0658e808ee7338dae834c5ea0eb4e4f9f7ae73ebde26

Size

18.90 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0ca5f17fc14eba8696eea43f6732e2b4145a7031df49ee4c6269ecf252dbfda5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:15afe16e8ec7ff0f68e653b9cb52efcec9dcb2f5c416532da8c67ef6d65f4563
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4899d4f4fdb1864214ba57ffc928dc1cb94f54a23973c688caf476082b434987
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:3578c579b0f0022c5e7ba0d226f60e27484d9e477472b875953f57b10634e000
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c63f56b48483a93006ea4a3ed32e7e7fd0320ff9b4914b8b1bc631cc840661c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:cc2a6faab813a15225a57b46d71cf23c47774e01c5bc7b0318f74df1957aa162
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:c2e3033545045244640d9f3854fc6425de9707714ff0360df8112d3893d7a6ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a4fa85ed261787417caad522eabd8869386f7c5bf31e28b12253b75f2e05ed78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8fb4d003142f89ba47f254fc4ae55254e3a6a58697f0e7bca3cafd0d9ba34eae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ebe451bf2cb78f6b938a409437a18f0a68343f9cf39fc3e1681f9693a9b76306
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:03a275f1c69d4389075080a516e5cea385cac3826c6536e7c8ec65d65c676df8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:de3fdbf6de07e6ac005e840652e54252a1739118af71cf2ac0b86fb15d412e72
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:aec037c560c0d266340a00b2fd8e5cf4fb2176cf8561888e28b81d350ffbe5b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:6ef0d38b5f52591e28c6adc652d3c050a1a7d6a1ef14027e6e59693c28aaf862
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:43e6ecb640c2b3f15e26d0369400b3afde81ed0b7c1692903a8dc4ca1fe32924