Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:4bffcaff3c1299f72b10990ef4d0c38052e5aa46d5bd6d3bbe2fc2b5e5fc1417

Manifest digest:

sha256:fc9adbe7ec8ccf1cff6516ac8ca99485cab845ae8e01a6e4e5fb0326aed89675

Size

134.28 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b1367b6225ffbacb6564de8104203c376d333ec0f5557102a6305509f7a03a6e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:34e132f24ad89505134ea04e2ca226b43d2abb750ebf83de53de0d97368ac506
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:1ab411d956da93006b880709daee5ea73850788fa4ada32a1d13fd61b2ab79a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e1009360235fd89d38a6c2ce146288e1f38ecafdff3066ffd17cc1e6b9651074
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ed76e643f8ba9ee6ea1b9420789aed9a720c74cbbd363619f934fd2838b65483
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5112aba6f86d541213abce84a560e3531c7f78999e73da2f3791e700f22d48ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:99f24882550d8fbd150002c88475331f050da30a726c85c015a2d1f3f5299a5b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:59fa8bfa3911312e0343d525a091312c69ddef79256d89a873bd0dc1f5afd344
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:44a22ceca1904bc21d16b1462ce5c4e0dfa524fc050ae63e1f0303f47078778d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3081f152bd03ed71606bc2497ab583256e094aff4d54d3e6c380ecfc33f92087
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:eb4f234ee50ff33f3d5a683d41f083e7a9d64fe6aac396cc0b0ba26fa531dada
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b0acacc21fc978ac597d94aed66c24291d2e8416a6e05115e73b3d150a9c6032
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4096b12f090ad682008360344e0b26d49e067e305f3764098e51a9c062518f55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:4dda954317da77aa51556417303df3e22e75ea69038734b07cfcab013cd17e8e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:df86eb52d1311bb30dd3d9f3dd74042bacb11db555c85e75597f785b320f535a