Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:4fb1333a79719dcfe159d0bfe51ab356496642fc3c7aed55a3ed860c840a1919

Manifest digest:

sha256:d5086a59c8c914c651bea25e2436af83cfdd9f4ec551b01d9a6116406639c6bd

Size

134.28 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3c9d27ef2c1ba225901eda874d6d6fd86c836573535e6434430aa74610b31a79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3a08be52846a006583e48055ccb597fef9d4f8861d39c7515e4fbcae4286e33a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a198800ee78c4d8b2cf83aa22149cebbe9170a28107b21b96e3a785f8bac2e3a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fcf64e1a3cccfd90b264827cf2fd3661d26587dfe6d9c4bafb9aa222ee541350
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:69ae67c734c26b248932f58ad78b95199d07424a55fa0a4cda6d6e222761b675
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:83f19b992ae39437896eb73166df3bd209497958cece69bb27e960a603908f02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:bd983d878c0eeca718b9981637625be1c548fe9431d8d2c39c5e5131fc5f5ad5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e5b9ad362ab6d12e7ed25cd4d6b77784b84273e9ea9939585b4adcce3fa51e6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:843ffde901de6ce4ebc868d6a2db4b99cc1aa8e06c6cc1a44c7d17c896a9bc70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:4fc0eed592318c116ebe44c887cebabcc25156b20d605b77caeafb5a5f3a1708
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:99e354348a7783f933cb46addfa9808d4a6861fa52a919fec55f43578ba29714
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4fe8a06bc19ee9e7345334946395aa48d4bf6dc6d000e38c9c4bc0fefe542347
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c919fe171b3fbde51452964aa8d4b857ed37df121826f06c25c9dd3406008fb8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c276c9efe5dbaaf94c3c19d34666d194bd7bbc9bb84e5d612b9a3a8cd67839fb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:52871eb49be6b01d5c0e49b3a301ce126af9ba9fe4c4319c60c2ddd2472f2395