Ruby

dhi.io/ruby

Ruby 3.4.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.4, 3.4-debian, 3.4-debian13, 3.4.10, 3.4.10-debian, 3.4.10-debian13

Index digest:

sha256:8bac29415f506675f7b48def227ba35aa7b4f4df90f0b54e411e63d55460c5f6

Manifest digest:

sha256:b4dabc5a4b82f8703a27ee7cb09c4ee61da5286c2b4f2a9dc6d695a9a5a832f8

Size

47.69 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a7c54bb38354fe0e9718b1cb9e10ea8c7731e928e8a7d61d9130ad1da33e6b8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8f4b7ae7ead3b6bba6092569d93b1e05d0c32a393f0db0ec6d8612e6b8d6a5a7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f35e3d29e1a1d0bbc0da07cf8fd9661fb4387e60121a63ba0ba3d689652e182f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a7ec9e2f33a4805daf176503747b061489137bc230dee6fc3fa044323512fc1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:82be4881c175081b3ce337cf14af4613247a94c5667dd627ec35c9acfb69f792
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4e3e666385f6eafd718b7672751b264732d57613ee692b75cca9115e542a12d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a3da486b2714526582a3168a1db7b0533bf18625fe33949ea4a6708befb1a436
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9894b76092d9914c97e86e5fea023b56018a39a9bf700584124eea958d166d75
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:28df6493d31dbd39058de90942321a93f80b6f8537c3910bdd4af14b6f3044d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:2d5bbbec5f46b14cf42a01880430737171a387d5f372b37b5b6a7963edd3da2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:f245c894e0124cd69908c9e1c283809320fce270210a2c74931aae22b339e9af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f5be97642006365e6ce10cdbed086b4229f43f03a0df880118be8cb2d20eccfd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5191dba7fcebd35d4a35e3de80b9615c5174107e897ac522e9fec2667cd0406f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:49d235cbce556f2ae7b6c4265062e01bba9325ac01e26af7cd73f3b83076233f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f84eb9c673a8d8f51f46d48dda127c6995724f95b4dfe980f4d48da77a41b8c8