Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:5ee45ce971076d049d3db9be0277e788db560066b78e3e7b6c796985bf0391bd

Manifest digest:

sha256:3645d3c2e920221b13883a7231e43265346c2fda95b8b49390acf9c1bc711ac3

Size

20.30 MB

Last pushed

52 minutes ago

Vulnerabilities

0
0
1
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:34a4efddcbc91f4db846469e8919af88967d19283abf974d9b548008d6ff593f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a7b36be929baad9e28f48d1f206b0f499c3241305e3ce0468ee7814e3dba74b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b8c831a1327b1af4aab9e38afe6fa7b0548b61d7c508037c9b531fda40e1c452
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:02d95b8ed4e42829e47e17c2ce26de76c8ba89d0a1476847758a5f1a33f05a70
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a56708717323fb353ee7aa46686f2d758fa6e874ba59fdf3e93c1ca7b9ab4f3e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:089883323fb6092fa58cb7cc3c8338f33f41f450b14850b508e668c1faefe06a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:74426faf2a3f338b3c2163c0fa98fd5547d2e20bf96d51aadb9b101b6cb0edc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9ff9f480288a072fcd6d2b55d1a85915cb01bb16be583465113c2144754d533a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:fb737cb81f6c3958be252c7fa29024fef2280aeffc0d64bd7a63ba53a0b365d0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:baef1aed4122b505b8044c4a5cf94f21686b25d1005a5020c9b8dcf9501b614c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:9313cd564504e0536489a804eeab5c9d3ee8b9795b260874605b5a0c7ccc2825
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d2b993e0cd08561c4d80a8b49521645f2820fa1a044d71c1e06f469896067659
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:29a43e072de610524fbc5088277e333b1a3a860a24cf666ed123c849f488f7f2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:82245a378b5eeb90dda4cc93bfef7a6894e7ca84f5e44107640ddc37de99d438
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:195525e7a3964f639bce44fbd617e2be8d6a8dd7442973c9c75ec045c4df974d