Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:ce3678d27257264a258fca712a6dc2d8e386c5547ea908dd4039e26c552f03c2

Manifest digest:

sha256:fda66f4c87b51d9dcd65b10631e42c161eb2bddb6e9dad2263cd553f36341b87

Size

154.33 MB

Last pushed

16 hours ago

Vulnerabilities

2
3
4
25
6

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a79dfccdc2802275f864c0539d24f7e7fb18822c29d55702e0a1d9576f1e1cd9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9a530e1c6a0b18d1edeb346256da251196a0956fd07b3a7f3a1da76af11b329e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:81b2d307f44322058d56e119b25a976fe2843b0b91531dd0a04fc48a84d4ac1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b8bad04aa4a969b1e00ab6c9694e1fc9f9a122dc7a0cb07539ac62dea04da180
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8aa4f23c2d2164aaad139e832e690967e3bb9d6903fe0ad467ede52a451b78f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:6b04969c1ef58fd4e7ddd700069212345b57dfd9a0e809a3bb8436d53cad489e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7e5bb64c5018cbe4e5dfb86536f2eb6ce305664f54e92c318c0b652e3c5075f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:f7dbf85f8002ff96350576544ce3e3d44786b7ebdc6a5591013a5f689cdccab3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:819b09ff770f2129112a0c9106bbaa925365af260fd8f2ff7a43ebb185f59d3c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:80db6d52084a660b383a04314912294288ca08a04ac5bc0991341ec5c60c8eb1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:cd171ff64f42b48c96f3fc16d36b8e0d78df882dab415ab74066fdb3bec2b6a2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:31aa4c47ea2d23272f6895c2633a856cc8290147c971a78b116553970b192167
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d9d20d0dcb94622102245a3f203a7a7c96e8bf49dacf3bb792dad8bbb1370473
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2c6d3cff9d75706c3768aac6b08abb5d2e5bbd65bdebda39823f9c2b50e26bb8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ead10817cc7cc56e2051bfd3bfc7db757f01f198dd9c005e2125addc2c327cd7