Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.3-alpine-dev, 3.3-alpine3.24-dev, 3.3.12-alpine-dev, 3.3.12-alpine3.24-dev

Index digest:

sha256:547bd4299a41a5f627c55b9513bc224c37043c5d32b09361c0d63048a9610a9a

Manifest digest:

sha256:7ab0b11a1476a7258a26d874c474170d533cfe667058030022408df28770f531

Size

93.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:031ccaab7e8e39d3e72d159374bd612985cf44cef5c8c309564dcfab8fce89c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e8b0d6dc04f2aff6f833b130fc34bb400c9f4c7680e1f19f01876aa2b49e9693
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:22e4ae9ba9f019ded58bbdc1dec0b3eaaea696f987fa866d7b0a234626b99a06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:aa089829ac376b37d9b8dc7661878434ccd514ab8481bebf6db3d5297636e6e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2b032f55adcbf0b1d17384755b1543b7d94f9758ea48164ccc0cc99dcc390d35
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b55c8372343d430c683efce828a9da045bb55ad5c3cb76f10543d181f856dda6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6c719c756abe8601a24fe56a6c65de5506eb577a2c545bf3ba1cdfa94cf5f6fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:579ee009220b3583c0efb6ed477cfd95415af21a44bc5ff0b0f52cc66f6d55dc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6e6b6aa37890a1332679505c63de6556a085a65f00479a123d9abde0f35af82e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2a88d704ae3092764f030067274db971ecfbaa9a01eecb07e1894b3ee2163cb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:fea53b6791cb216f20eb7922b27b1ae19476e6c184a7521204399e06a3912f9d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5472dd366b5eacb845e92446bf37cffa6d980b358b2291b3a693715b5ef9caba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:82023230b9a136261d55bf50efee5047150714099f454fe8e393df905c12efb6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:94d2a16f382d6a0063471296c830c6603aeb5bbf32afb78364d59e310fca36d2