Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:b7608b5f987bfe39e0253975f90bfdca1733ba202476b624bf111e6ff9601e86

Manifest digest:

sha256:a66c4bc45af526115f1f85a8986fc9fb8dba0662b159aabdbfbdbf04504ca1c6

Size

20.25 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:42e77d049e962442fb07d5fa8fc004917b7d0178503f43d5644d7331e7b255f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1017b3f44d16d23b7a03b2994813f47cc81d8126601e0802a96022036ac7a128
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:27c0b32536941fdec6ddeca1172ee11cd396bbe4c8182afa908101d2edeb30a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:84bd4fe1ee4e37151acd300718aaf3125339d7d35016f42cee8e0173c783828e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a6b4224502a3e5b7c62c319a2d6a46956232ad445838902dea4adfd673806565
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:04acbadc6973a7f1116e64f32248e4b313dcf8b8c35c283ddd84ead07b3e680b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:afb04e7e2da9d89963a6d9ce3e5bf4a94b56fcd2db23c544f41882a8a86540cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2fa8e46ca7dae4e5b843f4615ce7713e57d501b4babf680d2a072093b6293fb1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c19f48a62232ec172796b6bc68691aeabf21be5d037600794dbbac31c18c1211
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:34ed1d2eb57a071a840d4e9b4c2d7924a751ab6827cdda2c1c04402bae61ea3a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:544a0d298af19b885059d30fd4d97d48e153369ac72d9ee71723fdfb9f3d934a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e3d904bda24d66a51eafb064c84caffde808f75921883734943bb1a8954bd7b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:67296bc762535033593e6c91932335436dfbeae930ff4aa823d94d7cbb8a0be9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ff5b8c15b730512cae9ffa00b9284aebd0d40007afe380d2c7fc054d969c0098
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5be6ce2467e845e13270fc3263e83cf823b481bc8c0303e3329637d520c91339