Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:a83ca8e7f0ab03727ef1e1d2036cd231d634c629ef078f158298f2c03f629221

Manifest digest:

sha256:55f03ac52c7f44ebef8a917d710df9fa2812b052f101da3f6e77fb046922ba4e

Size

135.09 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0c9b8f59e0a0ede22112ee6ed0a0bc6261372a07e499f67ca5d7167aa4219716
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:58245ee72d410dd27500d81309c7660b907e85cf295eed7f89f41e062d032018
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ef9c7dc31ee43ab117b8764e2769f60aa9a6788d6d77f0e75d4e6bb26eb07961
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:25bcc805ac402a90a2b08c49d6cf27fd3fc15dcad2a3fdf0111dc9df13e72d62
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:e31ff8ef9fd1ee8c8bb99eaadf97b98daad237db958a506f08a71caacd93ad27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:305d9f9230ec6c3a9d61e5feae043f1558128bc4c2d28cfdb524bd87ec492ad3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:868afcda498ab2e5761d088d9321798ab066ba0cc7683bb120198ba9e4669c2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:daba4422504c98aafa97a5c5f7326d97541032100c0edfb7461c72acb36b3e50
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:081fd933639e86d1c0253b3b3da725de49855be02ba73320e118f45b68f7cb8a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8880b55e4d7195f0f15280c322f089547b77819fa353e3300e76b148c67b3985
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f18969d76ff71a569f546adfaecff2db76679fae9b7a1adf8ddabaf5229bb459
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f776f406557a41094eab9376f566c4777203935ec1041638ce55762ea52da0b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:78c7072b9c6c83ada7b974244ec6bee31e57f62c68af08c58283c0eecaf1520d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:937cc88cd4f54939538a32289886869b0170c61bee03c928dcf306747862dbf8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2450f6b3c2220c699d2b407d0ff5227715058e988ac5b12131e36000cd1c3568
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7298813277d5ee4e13d1dc5efac35b58a4f9c1662c61251fe50c83e9a4b96d62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f0c71a42115b5ef21ac01d15e27ef3997c66b7abbe296c7d5594f89e083574d1