Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:654ae01c7723a5e9c69746c63872e6d60ee1e85d7fdc0087323d849fc29c71a2

Manifest digest:

sha256:0629ce53fc2f2dc2ef40b24109b4c63b4845d578e6ccdcf351698b85e727edb7

Size

20.30 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1854dee511deafbe9aaeb07b4dd107e4193179e4908825f7c7d4d68c629b2732
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:453d5195acaca6b6452d3891b7081112d59b70229ba735520d609891f5c0eb7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4a7ee356bd448c13a91078c281b85f4a1937a4ab69d37c9e3907393fa7752a44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d8b05939161723afe2b656903c20d8c8ee1c84b0ba680359b1950c0d20f0bb55
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2c65b8b1b6995d60aaa4e3dba4f97e11dfc28221bff45e3dc4741aaa43906738
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a8ff5eadaf019489a97d04bb0e225229136bb44af68c55598ec2ce9558c0556c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:40c19ffe92ad35e6d82ea083e32336d0ccb0bae9b5e3dbe9f1295c7881499ffb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:84f2998d2a49ecfccfc86899b183dfc985ec5af208297a2942477e36ae52a78c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1001739acc0b971090f7b51e61d1efc10e66ea74b5be9c78acbce0f694f5a8be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a0b0f9340d33c8d94de12526dbe59fcd93197ac25e3e7b0002c87e54a52de70d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2c369d6ab579b86c8a2b8b42a1457ac780d805e0c1af090f32189b5e63ee5df4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b056e3e6394fac0ba5bfca0b0197feea62a5198eb0c980f70dcbdd45b675482e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1bf9ac034c12d41762e846125bcd96d85ab858e6095efb0ed929677c958f9330
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:23af23944025d43a6bdd11a00a571779aaad521b4a21c94ea60598cb556b7eec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9c9d719a0d1404dba6719247c9074d446af7f2f3a6be70b5a82f020387562ee3