Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-dev, 3.3.12-alpine3.23-dev

Index digest:

sha256:738cdcc8010260871f0aa0e74573e198d1ef73201f310f58c2eb86e16214c977

Manifest digest:

sha256:e37ffb778fa0b7984bdd9828666af6f10996a3deb6d7657a50e2356d178da7e9

Size

93.26 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0ad5333d3dc70a459ffbd62e17e8967702388841f36645fcfa4170c04fef81d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:99a617e6334acebe8f7ec1ee264b82082601c87f9d368407806b06ae82961a86
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2d6803a2c502dfcc2c886675f39688f7b1e0587f3a8daada125a0c1c5ae9a833
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:18dda47b72c67f4762bb09ee921792c40bb3cb9866070b770bc1abe24e216de2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a4ed10739322361c5c5bc6c3e0426cdeffb863927fdf5d2578d523ef8576c136
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:870e53bd8de0b1e45bbf09662b17a3ddcf13a238476536be6f6951ce0a536d3f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:50d98ff4d3ab249a59f187eb4e0465892a56318db89614ab143b5673fe59ae76
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:181d2b5c934a5d823c9029c6cfb44dc4e7c5f488990b97c9cbdbd92b16c7bd92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7fb3f245f35b2524a5c3daf30f6a6274bf29ee7093dfe61de062e264fe13ee62
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ea6df7a96b8a3da87429e7709928c910d49cc66ae0a4dbe97502d981d13bc146
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8def5442fdc6a33df1888a59b5af78679777f30d81a820292485db305dd8321a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:88d33de6827bc365d3e7c2047277c1cfd7b8c16589b6eed0cfaec8ed3702d59a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:89a51de28f6b79cc347522afa8a7073f51ece5ee9f1a65e45b427ac692c1704d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:10813623adbbf0f936e0ab7c3c66a33c5ab60626d09701bf590d73697daa1300
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b10b3b9da12c144f41122ed85a2ce66e698c035e92217a97a23a55b6a68650cb