Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/arm64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:f23c23b6a94d30806efdc413a91e93eac61f9c59051ed9cd3627a8e605f328d3

Manifest digest:

sha256:c9cdd0201d4cccf324af73db09f7cc7f0bc44433918fbc2e3d1554533db4415b

Size

20.05 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:415670af0ad030a5e346eb878b2e51292bdd407bd61c55054d8115deec3c714c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:26ce6f7e40640b465da960444c256231adda94d713174143d6eaa261cb00c5b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f39cf30c11538e126a4f7a16ab187a39e486ba7f28dc54a02ada035fedf14430
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6ba28d4cea29073c30ba4dfc5c7348aeca2de00c7d9f0d3112a2771cd19ba199
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:cc25ca2e565156dc60fe99c6f3626d1509fe40ea44e0b0473c68653f8282fdb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:aff2a180dd1e66dde1623f6c1c68aa64721bfedb1272ef25fe0a0a6f1c93089d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:807997ced7f4cdff159f7ce1465925dd606a6c3bb7697102105a47f0f70c7d7f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d89a803d9c0cc85916b9eff9873080d0779f2fc3af79a6a519e1c22b55f50c81
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b222cf97eb1c64ba81059bb0d2aac7a5943828f423140eec7f4e5d8cfa06fb70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c47194dc117bae67fea910c4d36409123b115531916ce3960cf0af9576e45ac3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bf4c1adc7758c349d59e1aa6db5edf55095e4574ba31ccccfe5c0f4fffc77925
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:9b7d091147097dbe7f0006116d14d7b07ad36f6ab3e7b349af359f9da003b7bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:cc891cb9ea1cf8f99374c64d8323ac8a0be1a4935c2ae0d88c70285bd2ab6475
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b84332ded48fb2324016d3ec2291ed1dde0e43eb5cfdf6d0e3e49bf2a9b17d09
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ae3ad05fa668f1e65c917f100efed94785efd864961f5dc39bd9392aa997cd80