Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:047e262127ee2a0c382f9e793ed00bb45c8ff50bfdc0d9cef16d5700a80b749f

Manifest digest:

sha256:e8d7cd2b7d9221ba56c9d016efdbc01a7b472b6cfc7526c691d2df4d3966dd6d

Size

20.25 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:452fedfdb5f5291fcf5afe29a67d23a9ed36ba88859e8003efe20a48e659cd51
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:01f30b36d7dacf3c9fa4fcf68b76b5bedece0aa3b2ceb861b27468bd184bf665
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8930e6acc0bb0ea81052eb9ccd9aef246be1bf57af2d1c1e1b09b993da6733df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8a9655e7dac24cd2a39bb6c4dee9c7265c2e018b49e5b07d582e5817c66c7735
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8bf1131477e315d2676e63455df06aabf4408e22cdc3918ab2e83fc97c389ea9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:60d074c467f83a1ac025400d0008a12d5d92b07c8ad0fb9e5dcf4fbc0df88b4b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b79e691a552260f86fcff611e970e0a8a89927ad2dd757fdd0be948bec4e57f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8d45184ecfd43d84c29c2e674b6dab023bf7f96710984d6a11f8bb7f5527e0a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:44697de4af87a1a45b72e75cd5a8d468856f2a82aaf325413962ecccabb7ab0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e3d4540acd273beeca20f2f8db8af900d98f832c6a9e318bc7d75ee8de7410b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b073b91bfd6953a7682d6e541666f532e923055d04c0f753705a3e3fd9af749c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:63cb3c284b778047ba8971ecb1e3e8db3614768c269370ed516ff13edeb932e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0e49165aca523fc38abd97bb1d562dcb83d86592aaf28eae3a80fc6e2733124a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:bc483b081cc17af1f46dd4fcb6b09d25e35440d3291242ebae0bd753034276a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:80792f7a9e656acfaa9f23b2ebfaf105a6379c8e8203965cba564b56af5128ac