Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-dev, 3.4.10-alpine3.23-dev

Index digest:

sha256:00d8bb67ba9f13018064ae158d5ea8f3cddcc5c8363eb8ee49759a5ec00ee716

Manifest digest:

sha256:db24ca54b50dc1245a5e88972e5f0e0d2356f2f85ce7bc44dde5fcad1fd59992

Size

92.87 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:99eb64d5f2f0f982ac96bf913c4062acc8ec914d31b1645f4d5fca5061ca7971
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0358775638edea9bffc1113da30eed2fc019a232f4989a6e4a882a01c4cab939
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c22fe7833b65f1254e13266feab284a0eef65a722a741b4baf818adc32e3bcef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f8fd299c80a63a7f88c34bbf9bdf7ced4bc25f20f456a446927d546c9fef0d01
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:3ce1ea05d7356ae55ae8285b997210f66d15797df0d1b856131837bebc965c58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:31fc2bde2316fde44085a1bf897bca077d7c83bc5b55d1d257c2897968b02720
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:20019d4e6b4190f3ebaeca215e5d30a52e234e9916f055125567e976637be752
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1d5aa03bb9f8d757facb3f90f76fa76bd35f902f51c5da7d5dfd520f02b30c46
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f3f469cac43d7fa73c9c26e6002f010d5a1df7345222f7f4486af8abdf8d5cae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8bde42fa20c12a156b4f5a68d6ca653c0ba89296a0092bd27dd0b4e2bcbe0d0a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:97e70d8dd3bd8f2d7e422ec75c0f0d7fe252bbf0699954a9d9142a84e747b174
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:90dc1a219bc4a447880ce32907007cec307236183f85a0cf2fd4a87e388c7c3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c2f481ec4e5aaebbf68ab496daaeab55a20a7f8d405db04595a81e3f8e977503
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0792f84faeb7af2bf269c7978520f54674b4c9dcd5021ea3de1d9bbfb17d5a4a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6eed495443a0d9a372939f6908c77b385793bda31567c100651477f4d982838b