Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-dev, 3.3.12-alpine3.23-dev

Index digest:

sha256:ba4789b203d8a5b9f32c69ded62db77adea052d2db24268d33f56a1c7cd13785

Manifest digest:

sha256:a05bf029593b905c2a7517fcdb0eeb7aa317d1d0417a5a475a9657bcae667c80

Size

93.26 MB

Last pushed

5 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2ecb41828e159217bab518ef44a54d31e570f0c243d943666edd74911bc993ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:6d39d8bc0117aac0f3b3f5408599abafa52fb15d06f6f88143eee274df40687d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d85aceee79030161a7827f9fdf6666cc8edc4950a5e3509e53850f85ffc16fec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:79005501149e4f322ef00bb2039f80b9b26f1eb8e475e2e607d0af457365f30d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:fa548a5469551dffd5f9e8ccbc5ae59a5269205933055b1ef72b32aeb6e5adf6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:fa57698a5cb72f063975007232bf8bbade409d8123388038b8a2a03b1038542b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:64d4d6b09cee3737a26fc003f1ac40d9e25df1a653d125dc204e69c09dfb08f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2751e986d904f33edad66047247f4ac3f6f4d3835a0dddebf4160b7f3d2f7ea2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:10fc77ff9d35c3ef14809cccfe7a794ebf52f986c165446051638bb5b3e96bec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1cece17bce06b8115ea54eb9767e1bbd01c3d5899e89abe11b08d7bcd7d008b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e4a5aa64fb58c9fb98129d772d182c0242c23a1045a17f0703abe5198ce4271a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:046b28b3c372f2b459e597627fd505782046671adde0d5115dea1ed245036989
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:677bf2292832fdd3ea6f1049a5633b0820fc0aa3d1bb8ca1d199e264d481a8e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:064b5ba9a514a1c61505c6e177b4efabf0894aab02ea4da10212a92189616095
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5e089af1da646a47d6563badc621b85527c41c79465481e2ee452e6ba8cac208