Ruby

dhi.io/ruby

Ruby 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.10-debian-dev, 3.4.10-debian13-dev, 3.4.10-dev

Index digest:

sha256:79ecafe190f2024134b216e1942ff77d57bb025adefbb5fb50b20f3112cd6035

Manifest digest:

sha256:1a581fd8b1dbc1fe1b1388f0726184b38b59455e4ba932b97c00c78139c9341f

Size

157.77 MB

Last pushed

16 hours ago

Vulnerabilities

2
3
4
25
6

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4371887330469f9415cb3cca422e9072845dd6e5507405af32332273aff553dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c74be10efd005b678c8d7d6035aaa555409b222fb87dd5bc0eb67092239d1d78
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:ed486897b665e8197302e1d392ddc186fbc9b55a9302f1aef81d76c42779c2d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b94d437fb457ea185be59906ef9d28a5e685c2b97a2654a54755f4185fcbe6b8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:00b5c3e5fba37501e46bd29cd2092d141d9158e16e5f584451d6e44412d32e2c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b6f85dff0038ee1f513ef1f141f1f8140237546ffba0b0aded2fad3a06dbb763
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b2cea102c1048bbb319bb7983ca3889ec7995cfd884a08e94b5647faddd972c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:26eb10e1243b6e71b85e1487da5917d693247b1569cf09472fcb88dc4980b21c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:213f341c160957a6a9cde173d06e01fc4754fbc443ae04b8e9c54e78e95a167b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ebe74504e512a476a7f54c4ecbc1677f71106283162e670fc74ced1835e3fa22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:20341408712347041f420a7632771a500697d7809e296f28863a38f6ec01b52b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3cae0ef5e42413ac21b6a814a979f932c7255db8f44a8a1106baab53acf651a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f84d1bdad2efe93a362e94df2b3be5baab600b57f220a12bda7ff3ca600efcbe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:50a32b32b99be211a95bf8154e80aea89912141d68a2d8040710ce026224fa08
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4fe89ffb2b785ff7898b9b30a395643adf138be62dedf42967798ceaaaa94a0e