Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:f4e5fdac2f1a7c96814fd45baeea5efecfae0a3a6cf2bc111891874fa821c9d9

Manifest digest:

sha256:68dd062708b333c94e13afff17ef6e662b87b65774d8fd7305530b58ab6b319d

Size

154.29 MB

Last pushed

1 day ago

Vulnerabilities

2
2
4
24
3

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:626b31329b415d707857c16a8d1199bb5a5eedb21d701d9c6dc78fa8537004b0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:df97219d0cd586a7d62ea6d018ebbcc8bef02c04ed01e85dad7856b1f08d6c88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d3893664f6db92f8cf28bfe73525e452701c4d4e77b18ddf749e60f9558b2b5d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:794575317b8ea4802c2a75e8d49dcdcbc099c90aa165fa2df163cf86284f935b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:48d84c0c75caad7007ea7dfbd86fd3cc463147fa86529bf6ab2dcdd03c5500f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1982c8d73ea2f4cd4c7794f7d26e6f000d03c0f9bd55158f4930873ecf7ec550
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:072b428174852504b4a63db7f6977d43f79519bc5993d48e47db2321e01ae192
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:61a485a6a2ae318e1683e811a25647b46988136df9ee18a07df2cdaa8bb3fa68
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:9a247ca3a531e9537fdc110e5bcc51967460dae82a5cf0b448b2833992974593
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d9e66765d21b7664c88d7c0a6830a6be74bf8678cf8d562c9235d71c85cc36ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b462262f57a998ae99066c51e07c34758c011c66821e603e254f29e80d6abf68
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8da98497becbdbd744b69624c9b21c8960b32cb7e6063b90748f2a13637b7b51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a4ee1c7a68c7856b8789691f90c367a72c786c72aba8c717a5dbde0a24b47ae9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:8857ae375a9679f2804a763485a6e102b8748395f45471c42f7f60219358bfe4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7293433fa15f29f7f69460eeaaaec7e181fe10074581afe6c8a9c3db4555adf3