Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:286347a667aae379ae5a05d0c5f0bae98d3bb44d1d289c7dedd02b7de62194ab

Manifest digest:

sha256:895b87ac5fe7945c8678d97c8772250736018ac97f2086ce8b66124144f5b0ff

Size

20.25 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ae67c5f5aaee627c30b90c6328ba776b1300ddaa1dcd793c484d51e5e9bc3ab4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:263ecffbd5991d48c2f04dadd14b1eb72b7a5bf48ff64df94df424493cffc4f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b3c5c76c369be46b3319f9224f89991b29a91965667673fcfdecb6df3b054dbf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8a12fcd715bfdaf623e59f0e212826cb0aceb7be20fbcc6d7d1ca66811752e13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5b78ffcbc12f036088096bb032318d73cc4fb6732f83b81653c48ef026aa699b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:312a8ce8a5734405729c0dfc52d3575b2e18ee9c044790b9960727034556b61e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f74dc4d8032d25631fbfd72ec446a250764bd1db8d315f35cfb446ec73ff17e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:918570b3a0294d1a19682474398f19a19010693736e2d23a5452a83f3f9b441f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6b11f2a5082f0ff32e3a59acfa3fb07a50692e030a8a0c39d5822d914617f1c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:069944712b0e3f36e2bfbaf595967a34897109b0f7c51be40b2546cf7e5b9933
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:aca712e1fad39c7837812f1aadd7a84e9a383a0f1c1809e9ea7ba3cdfd4ea035
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:df982d95ebbeba50567df4e1947a54a3f4627a08da90721aa087ec7d124646af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:b78d710ee8e1812b4fcb56f8fdb0348c58d37efeff61b816959741ffb7a094a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:97a8838db0c0810eb633caafa9beb77eb9f2003e22d03cdf4cc95631ac460914
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6977dbaaaab50d25b65ed3ad7e4df89f46f7376371f8cf632dffc50592cf7ba1