Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.4-alpine-dev, 3.4-alpine3.24-dev, 3.4.10-alpine-dev, 3.4.10-alpine3.24-dev

Index digest:

sha256:0b3058e090555788c66dc0d6ce6ae56d608dd9c3f6a3cd5209e00956dde99a4b

Manifest digest:

sha256:92db5b0c97f37951367e312eb2523f48982714f44ed74d01d1f68de392b16a08

Size

92.92 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:6d351eb0ffb47133ca11f52bf7fa58e7887d2554ecd575c66881811c1fb79da6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b340f20c053c26ea44d2048e2b6bb3cd8b1f9432cff90964ed00048e2aa9fec2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2e091d30199372ff760e13dfd6a1de695af6db95f6b8ed60ed586ea204208a4c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:68fcc8a2b22430ce9a51550d834736a3acd912d2c0e9d9a9cefd14ec3874ab78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:26e3042b6e0675476f85e1a93f21abb08aaaf8c942074bd7c5120026f337931b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:0784bc454d9412328402cfce24017961eb9b0cff0553da1305d2de0acb06ec62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d8b4868a47eab6cb4ff741d00b8c03b47eefdc229bfb584c029b6044dc4f6d35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:241aa5fe2822ae1818e124a4f52eac0d6b39721676a276fc92e8f26618075834
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ecdba648d4083933e750ccae38da24a50d7dbd47598259aa74d753426ebef8d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:917039971938effd43a31654cd6399e4afc028f39c7bdb9192798edbda3aa3eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c13b4a238cb7b428b6e36b84513ad7b1687bf02482134aa2ffeba8ef4c503c68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:93e1a47fc4b232e6e7359d25ceb3321d618f29f344c9bed1a6f5a6b8bb6b3651
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:adbbf0375d52cd4ba635f458683168a35e41c03101910b75f954172c2a7cc402
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:25ee623f32c120e282a0b75801fe98606988c3d193daf2f972d9e757636f5e16