Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:013ca429d0951f88a53886f62f60f3e61501dd183574fd572069793e75e166b6

Manifest digest:

sha256:2e6d50a527a8cf65b479b76f303e6281afa88a54634a7abaab226c230fe0029d

Size

134.28 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:46e82800636f49553ea64dbcc93d7dd81d21ddda6156dab57cdc7f65b90ae659
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:7d299e60c70b9c48d47a54345e9b83e7bb78109f7c2b8c60cb7a3891e2158ae1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:91bba06bdfa11216c254bfc0f1fb7e5769939dfe881ed2922829c9299fc49865
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9ffa1330a5880f242b884ab5b6df8f43a2f899bf3985d571701e07e8f971cdfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2339477fcd720e5cb7e90ca804f88833c6c57db2d400bd1bf9572665741db0cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:644c88f2e9d81bbd297333fc1f0f7dc85f23af270822a592e5be124d1d6fa64c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b27097122c568ead92ed898b27be502abe3aa7ef4814f3af0f61d2578a469be7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:65df8b1db685a42dc3035c9db9aa044ea92dc2841dbab0042adbb96d6ae82fc8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e1f21f5d19043e52e6245f165c1cbe26eb064067ef42fef960d706fd81725046
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ae996318f0c83de2dfee4d8a9411e28a491d1373f75f7b35afc022f49c4b4c80
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:eda3b5788b179ecfe231787e37a08cc0fc33779100e64ecaae506344f6861fa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f640cec37b1880f9d961bd6f3033bb73293883d62e58031fd3e0babed1657848
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a77cab5da9b00d4d7202109f1f0d81dc548dbf35f489b5eb2bd4e75d109f1f35
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:668ac0fdf96356957ac8006961b3add111e735a07cf786f97c1f9269f52daa35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f70dd4a762ffea70e151f4714ee80266ebad70702bdfac02680d3ae68a5a00a6