Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-dev, 3.4.10-alpine3.23-dev

Index digest:

sha256:495d7e2dc361c09f471a08df3aa2da4ee8b2daee9c8a781045dee7b306015a09

Manifest digest:

sha256:64d9612452bade1da6e9c69c92468f6791e30f257fb044643640d75ad7862fd0

Size

92.87 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:043252b8f3e9ec27a9ec701d360ba26d836e512e32534ffd94966f8e659675e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5e1a02d025033f0123ecc4c4a65942bd86a32099012f20b307d76b340dfa5da9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:77daa579ab8d54e59d5cd9ff4e0f4148c6f4883e10ed7b29b61fb1e3d390ecf6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:92b990690d9f329e85ffc5c9b9bb10023c6bf41f7d4bf97ba4bf185a07689498
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a80c0b69107f6fbcb100efad1779a634ea1c29feed68354eff88bc2d4b1297e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2d3f9334ccc213a250f194dca8cd1ebb5970adb6f8ba00b39cd5896547d4ecde
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:79d073a844636f9ff86fcf1927d6dd0d8575640e150497165558f01a5e7a65d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:621c07cf3280aebfd9372b713cd4994fd7c33dfffd1a70ffcdfdf3111143db35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:dce391559ff4887933f94ac0f9d52bf698b5c0cb47a6c556132f4400eecdba1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:fdba86d2da1426d192667defed13035d4e6ca15279852218120bd0a52aaebe6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:f8f15ed211735c7c56ce3cc98220b020d32dac0de19f77cc24202cbc7accff5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f0d6e0dc4088ed678c987a1dfd6a61dd4caca70414089fc9ca670de74457178b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:afd34443ef7b2cc4714c9dc5679cd2c507a7cfebb7cde58f0609036bf3f5d609
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:49b375c1c1fc64200c0ff58cc28f2212b8f12cbff8538b041f198befb3e2b881
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:205387f49d5b95d33c696553df1fa12baa3d25719a0a32a7f5227a5cc823f49e