Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:962401fb21423e797b13b48067620915b598732c289ac0f8c4038eefa9a7e6db

Manifest digest:

sha256:4d7b4e906f0393e5d556b1c455ed4951e8d97bead9846b3bff5ac9d83b95d3a2

Size

20.25 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b2341a459b9c2da81570e31e0a691669f96e307956c04e3debc0a04f21da34ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:54a5d83dd636907983a9805ec61aa232a6f6126bb5c36317687beeabae4bbdf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:e76430b606323d802f4eaa352c8f7c537392ba80b6ce68463c31ea32dcb069dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e4a01fd597982da8bea3de1722d146c16f7a2db2f5cac0cc2dbfdaa877fa6509
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:42b3dcf5a6ce96e9ad1b0bf600306afd71f2058f3c9aa70a690cca636966f9e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:72c51004855cf3ed48f27333c71f5515446c07d7d339e0951ef90d2d788fe3a0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:0ef38086d4ac62b95ea328971962144ad6ba6bed150dfcef0e8d2df3d6369ca6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:842a5da9593d83e8fdf9068a5d4c2c7d7468f8b10266dcc98e604cc3fc0ee6ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1946f7f8e34c6337c2e062ec641b3b292778cf372224fae75de2a987607b127c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:4183a6e78a9b7f004fc2c851e7ffb4b7be824a013dd603a0bd18c4f4244803d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:13d725ec3976a4f0a61582e58f84b01434183e3fe3abcb8cbbf8434e1867be0c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:ac9f3608b2008157efa09d84ce2a138a1596857daab26577053a660ee8959eb4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d575cafa72a41df46939e5a6b05977cede0a3c15483a307dcbd8cbc7fa93745f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:436a0d734f700b03a753fd7f8a987ffa65b9a7df7ded9fcde0e4339ac618b597
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:729bee9268aee86bd367cbfeb624ec4c1891550e6851825c956245203778eafe