Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.4-alpine-dev, 3.4-alpine3.24-dev, 3.4.10-alpine-dev, 3.4.10-alpine3.24-dev

Index digest:

sha256:1a750262a295967e5abf99da520b8b2605cc0b512cc3574180510ad63e81b457

Manifest digest:

sha256:4cb3288314c6147d93fb0a24b89b6bc73ef747ed2cd1f3c848cd4d2359f050c3

Size

92.92 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a3ba87dc35ea11742131c196c2696142b2b9eda657e5fd156a3afeb248c44dc0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:13811c0ed04e666765c7c15486ef8d2d167d237290ccace42ed99a00142b244f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:457073dbb8c2d3cf28e3a1bad638c86f2a3f4d8f836b9d7b4f977f0909884c16
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:2f36942f47169c44223f14d5c799bdf4a1e44d886680143110ebb81eb1901ad8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1e903c96003a051faa5e197dc3067d0e1f36b3ac114db950a0c7c1a473a12745
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:477d64b3593cf97325bdc04175d330efcf33be118ecd5d0208886ae74c93fae5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8e71915faf35a8ca5fc26d9561660bd09fa63b9e98a1a5f7484f7c341fa3cc28
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4e957a95f61611e2fc23bc49a97a1a9bc666259e374b944d47539df637f821fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f29c91ea834f9fcb62578efcb535598d8cd6d05e4d81ba0be6fa795bbcd4fd68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:856cdf6bd099440674e916f5311fc508238e2acde40042c90c3e6ce48b62ff01
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4879bd710642cdf0f8822349ddf581f918a8e3b23c26875037dc921fa157a22a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0f21d29e8f1c460de3f0698c6b247d7c4fa3f8e47ba0f13260416db9ac2a53af
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7f6f3ccc78b88758eb525b70d9a2ecb9a45bb486fbbbf6f0cebcf93a88d6486b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:217fef4671d31f930547de89e5c510c07bce816501989f45f0166113a3132a92