Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.3-alpine-dev, 3.3-alpine3.24-dev, 3.3.12-alpine-dev, 3.3.12-alpine3.24-dev

Index digest:

sha256:e0998da68d186d9f899451e4ead1f903ba364b6d223f48a745ff6d103d5c2fb8

Manifest digest:

sha256:d6990c3a6c5b4af470664ac9c3ec1b083f9991a49ae514f384410d4adf4275a0

Size

93.32 MB

Last pushed

5 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:677cf83dca9c158682d7bacbef8de8cc9103d6323f638981cde308eab9952dfa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0c76a8177eec6f3478d573090cb91148dc5655ea0f49dbfdefee3d21d4739b67
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:390fc20e173f10987b2fb9c8680c06cdba4d52c83452bc371e1a300a728bc267
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:738d59677492ac80afc6ce4d25d3cfdb18b4385263c4e3fdcd24e1adf09ed2a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:0d2401a3cca10e8403a6675b62f7b467c018782ea7c6ea7733adde1fcef1bc58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:13f2798bbacead5b87d7b23d3ed59653ac0874ec59de9ea53bcf7874ff1aa87a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c5fc883bce4f51601a3406c3643cb035f664a5583bcac6fcdc710daade8e5b3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b52b28ee4f849476058757ce584b4f5f4cfbd591977d17059aaffaf26de414f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:94b0594f00a4ea46ae87350f56d163b8aee128bca129fbb0bc4fb6f99adda40a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4f7b60cd0039466f67286d543ba473c4091f363e029d8fe35582a6e75d0134c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:dfb5959f43a18098938dd5fa5464d6527fd90de14c7e872985992632353caff5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:b1fc0d9c04cec489aaf23e2c4f5f58eb78b84192b914fd4f24eec3006900b5d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:aef5f6df6e58ef579526167c919d38c47ee4f9eedb632e569b8eb6d6b9723594
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:50c6722f6f68bc4d8ca0761c1103574b4d21451b47e9c33264ddeb9628b6150c