Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.12-debian-dev, 3.3.12-debian13-dev, 3.3.12-dev

Index digest:

sha256:37ef63cdd3f06b8d0ec08f97d149e48f0f2d0fc69158cd3ce350f7c7512effee

Manifest digest:

sha256:97962f9c5312dc3a7a299f65a6bf7dabf1c44ab59c6d1a1b4213319bd31c7a8b

Size

132.98 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ecc8f0a88672910015d35c12a4528ec8bdc179c09828b086593e2d229b233254
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5f2b2b75206ffcca113b5eb7f958e621e3f0a81fd2e3627c615d9dc49e7f7eb8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c292c64e7aae803fc76de127db2f4dd286cc4503c2d85ff372364d30eea8218b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:cb9d14f4b214ebfa6d9912758e6d11e986a0eb2672df80c030a2e02789fe656e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d03f061215f6e48c2dbf927b7f25c24d3f0cd35b5be0b4e9c4ffbd474ec32e61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:57ba1fe462f26cdc91c138d2315223a253f7daa984bfb53d377731f2a702aca6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:519b4ed8a63eda70055124cea49fba6d75308f6b503cf613c61ec7c11429079a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b7274284ace9bcc4784bc2fae18a1ead610b7ed113a9392c40c87225ec3c4b5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b0aaa81579ac230939ab5e033974b244cd53f28491d71141bce3caa9b9f2c9d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:dbd5b11331a899de2ba65f291d1e7205d1c5e17b2092657d16a7e289adff3759
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:31ed912cf498dee5a0620a55558cbf3186db0c8cfb8560d186d3e8cdcde82b29
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7908cbea95260549ef93d04dcbbbcb8bff9bb1c648d50b3f89a254a3d230b1f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:02d5b3e66017d14c3f7ea8be96a421fe8a036ed74819b0711848d3a819692a71
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:076c679c0656f7c130a924920fbc249bc59fe42d66e95ac9a27417b278c5e25b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:50ab209cd075b8400eb630cd1d34dab9c1c47853c150538f2b9f3e0d18b523b5