Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:f23c23b6a94d30806efdc413a91e93eac61f9c59051ed9cd3627a8e605f328d3

Manifest digest:

sha256:f1afc0f0a271ccb0711db1dfeb0cbde24768be03ceebab2c8c24b3245418d4f1

Size

20.25 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4065ad0fb0275f77d9d120be532ff289b165693a157e86e97dd21899f14935c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:23fb96a5edbe5720236745e4abcfa082bd2ee5d967d10b9f3d241ae9bd198e51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4b9dc5518c118707bf12d90b7c4554d42afdc2ae0ced7c8ae7b5787c0a9cf36c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6d7b39947a087bbf05346df5b98cf32dd4e3a04c0b8763139b6e159e4d462b1f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:884aa4c33cb2454cd39b61776acf2d83dfe465d43a1bc19c9c1de097eea44cc9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:d41c8dae7ecd755c9637186997bd6b264faa8fb72965a19414f1bf2185082bd6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:77d20c5ec7704fd3710809a5df59e275f908dfa646c1d0deaec8a349ce22aef5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:219405f0bb97623b1d9d691e20f61d275f011409732a4cadb92630ae6d530b85
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:588d7221afcc5b5e133286c0f1c9044c1c74fcaa140adbc5d59248287d45e8be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:eff83d62dfae0dfe97a9f9b2428c0a8d661c9532d67a4a2b35885854292eeb12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:85b215230285e533fcab959d4f580d1aef585a819c9fc434def8daff00553965
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:012caca2e362491454c2e7aca0e5ab9e447f29190bab50889ad0bb9c90481ade
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5cb8c26642fc23d2e21ba39625bef707f868860d9a585f69c429cf07a89a2b9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2b806b0804385cab10c03d5b69afcf80d34f3e8be1e27b9e29a0d23c0930472a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:651bb8f46b2b7ce0407f4d3585ca985bf9904dfb4caa07ced58c63882f3d8a5c