Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:ca57f299613687f71527c571b17bbf8457ed0e4751ac7a63fdf3616dfe693e42

Manifest digest:

sha256:a3fb43f5b161b572a48e8faa850184b4507bfaeac40a17e5e7a2f63b11f4ea52

Size

20.25 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:de654204c9b9206f85e6c0a750de4c4cc2af85002fa94ca3c4f889fb127ce845
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f9c66c25873b42b31d83c9377b4cd781d29d43033a310cfb2b8682fc91c0b890
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:07f9bebaf35bc03253297f879cbe31044d970b5ed3cf83276c3710da62090a32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:965e966b27147d0b7b5a61cf15def3f4151d866e4852e6ab0af29a4c6244362a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:6d5ec446553d13f853e2dd45f3fdaf54753cdcd246a6129473475ea7c409b92d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5064e7fccb740171c9656628b9e39999f6585afb76bfb0918c07bdac06cb123b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f7fa17dd17de89bbafee9b28ca0016353e801b1b6c6974aa445ba0ff8139710b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:4521b34c2711d6eb3e1f269f1286674c5a39bcf341e6a4e992460f45601a7bd9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:42c75757f2357d6b738c8b30a517d00d52348b7ce3f059e3d79cfd3380c1f96c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c2468cc37ef71cb4c7aa26e4d804633300c4a1e67bdae31d04aa448df1b3b3c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:7466971493b910b59a84e2dbff9aa9c4ca241d715fe9f80f6a132beaaa155bfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a995432a1a92764ad128eeccfe9f3eafae02c6cd922f950fb7ae9dd1a3e08615
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1c91dd7afc76810addce4adf145b2315dfed38a58cb030fcad75d1d4f4fafd41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7abd42039942f80cf510afc76f121437b9d43882a2317bd8d7bd49c95cfa7c28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7b72d45e86212e97d3b721d9354f867aa5ba9f4c3955b3903868680a0e1490fc