Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:30e512ccd243130386270f341768d75ffb864d0614cd9de28767d1466df58713

Manifest digest:

sha256:af7516ac069c9aa2e168cf9c4fe55e4505f7bd4ac83292b5d3584a431f987ac0

Size

134.28 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8529d698131fae35c094c585278cbbbec5989f32e62e8ce40dfd9f1917b2e6f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:db092c10e0bb050facc80a8f91df15940beac14809d8923b18dcc24bcbbcc1e9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c10b7cea85c19e590d68725de4cd7447b08c751bac189c9bcc3702b97bd0a0a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:7dbdba31fcbe355ab443b37d5dbd21bec5c10ce2078665ff59cf2558b88a6a22
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:3e562eb34589c54de4a787a059588175dffe30c8ce7d8efbd3437c0284af5917
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2b6dfbaff6fd902bef738febfb477bad97905091c290c04b913b93918ee28a40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7bdd2c3b75ad616febfbdaa17ea3620eb906b5db9cc04012f6d7363c8b4ff958
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:55c4b09d29aa265306027163033a9db59ad88f988ff3430f0cbc639e9ca89bb1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f06608f446e9cd3a3100651a5f12bde7fa9f56db6c5c78e2f2b6346bf15145c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7605744955ccadfc296416293db3d52889ae699903182354083ac21555aabbc0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:fe9264a21561fffd0e3dd69223c67b04b4b66750d1805e9170ec3e3310db6571
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d8af196a4bd9044d163b82b2e82c649d8c68fa1b62e027d4833122ab8d47f789
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:32eda0efded19dfc51505359c5c52679f0eea6c14ffd472ca1b1de10f5b93aa7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:948846322e84759a6f406f628136ec8627ef79faeb20f706633f2898b16aea9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b5242191690a9f4a7893c7ee58dc900809552da5e7e1fe2cb45259976c3a589c