Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:c4986396a0e390cb007648afb7fb7d3cab2a8828cf0b720231eaaa44d126dc3d

Manifest digest:

sha256:ed46578f596313a39271eb80374b5634711498d2814eb7748523d8085b0fcf67

Size

134.31 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
1
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:c5a7bfefece74e42cfe11f9facc3739d514b325f4cf43c3105ba981b0b49acb7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:79798f87b779d3f8329f8185a908bbc4bfab87e309c3fe175c35eb9eb161a29f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8c993ff00453a6fdff6b05b54588c7c82f55fb4499ba63b3419fc7561c653222
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1ce479326f6219b7ac4a9b2200988ab96fb7751b57980e862aaa38dff5a45280
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8c9ee6ec7a25edbda0fd5b36a45d1f8dfbde779544f1072d4de34a009a89f69e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:420b038fa8f4c5ee901fcc851a106642cf21f34099ef65b13ddd625ba9857b06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:69db7def738106469ec418e78c538e8c36fa584714e9ad428499e5983842887e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:23989d365c4f8fb30094de8d8fdd1c20e00c1a20d2775d0c4c834dd88a9d2ac7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:93df65c088066ed6947f43bebecf6a221dc0191cb535bd9266aebdf2f208708c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1d56fed365772b28b6d3c65b34b1566373414649807a6b384e40487bb9f2db6e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e32be941a5aaf2dceaff37837ec6e1b6220e82a4b7dd64e340886a8f562a7063
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:dc737c09fdad02f2b43c1570ba0b0e2bac37cc71597605b9315bac34890d9f7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:95053325d5ef96d740e1b125bcd9de3045dd29a6da9f112e617e0a5e087119fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2dabb19c776f29ef0f77395f705a2cf0c5723b8f698a6b2d2f17b85501558aed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e25fdb9370d093318f68b36a62ca3a1b4995b7c1bdfa1339aead64d0a673b5aa