Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:fccca3208fa8deabde48e0d0abd47310e340a7ce9e9945b6e69767a28d76a609

Manifest digest:

sha256:54f880df452bb33520601c48061c0e4ac1749e9ca66a11da541750e03088c319

Size

20.30 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b380e526c4b7a1cc8aa03f6e7a27761eae9749b00922ae6913ed3f509aedd7e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5e5d4226dc6fc640e6560a6310a83be3c33b5d2f54f6d1aba00615d039f1e8a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:607ba7c823aafe687336a1d5d28287ef5ed278563a647873ef146292b37dfd7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:afb86dd97b2df7b1db220e6d1697f825b4d0037e8c509578190dfe78d915ee52
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5bc73cece93b75c8fc7a10475a50b2b8302e1f64e3be9f726ffc9804e8973f9d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:98c540ebd2685c2560965d39ab89987cabce4d24b17a45a384ec947b5f83932d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4db8949a8a7f69284ddf4b8a1b1dd824a6d805793f75351c37de67f456ce19c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:13ecaf37956369c57e0449edb1ebdc2b67d1381934092b4ea4e50b8ec5778f8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3e94bc9a2f071a7884c33bd36bf3ee407264984c04f72477e9ec524fcaea7183
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1978bd6c2546e93ffb2795961f3ea7fc303aabdc8ef66ddfbec20ef351695eb4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ccd9a7410deefb793405bdf13fc13b146ac05d6e7c3fc891bdd3d8ad1df0932f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:190fb8e2493b15de158f7b324d6e548de6c3b77aeb247b474309e8ff42228999
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5eb86328198e07896a1401c49d9210cbfca6088f9bfcf1cfc848501848db5710
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:3a8cb559aad792757d7a82e1ceee28d17f95d04fed4ff4aeadd35fb0ac459f5d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:08ebabcf4bde14e650e946823adb500147808f1ebf98eb20cd0fe363975ee43d