Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:8a931049b33ea42598a07f8cd45e48daee28c84f1bb73aaa8a534c1feac9f796

Manifest digest:

sha256:1c5d4f83a4a29b26f59bdd7a307728568a3b699900c224976cb7fb2631e2b2dd

Size

157.75 MB

Last pushed

1 day ago

Vulnerabilities

2
2
4
24
3

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5c350382a7627cfb1f35fff1a2445b52fcf44fcf7eb05df24ea552f0fdf9abfb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:252aea26b68186094e3616719e827a544bf103778f836d77c6435c58efa95d10
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5412981fa7ccfceb40c7c7c0f15219e07eb662561dc643dfca058644821e19ee
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d1b782aaf6fb22fc15c3fcd18778f252d9bab1d1aa92c8286d67f95b48c76503
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:71302e7048e8ce9f68d6346e46e0f85e3d93fce8971f91a87be8a2c7362de881
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2c382d91c13c5c72837f8e1c1aebd5b3ea85030ee878590d79f29712f8c6dba6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:46538b1c24ee82ae0388c3a6ad76aa2a2544611a4cead0ab76c89ed27cdcee8b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b664b570d4d25136d1fdd585502fa8a051b230af1fa85a438846ce1a6073bdbd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7821813ce68395442b54379f13a61c0d5bc5e71b19a0d8d24ad9f1fb5d6753d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8563b424ef2d4d96e81ea325b69e65a1ce9fe9fdd697b692b697b4f2e1e4e96c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:523895aa71f28ece5ebf4f1a4c4b01a1182be046dfe01e12e669137450f1b742
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b958ca771fa007a509a72237a062c72ab617f393da8a179760bb88ce2d5ebb80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f3b6eec3472978eb4ecad60e8652e518c394686957dd8c743bfda2c05cf49051
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f8a11e1f0b32c59c28248513138dd380ac7b3fe2ac44026b728d6baf1f990830
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5372eb3b1751aa4f0e90fdc6aa7f9307af7c69fcdbd082edcb0c08c2022ba8fb