Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-fips-dev, 3.4.10-alpine3.23-fips-dev

Index digest:

sha256:6cbe1bfc64ccb8e4775c07cf8229ad7bb1f51e6071cd4d106e1e64eee071b8c5

Manifest digest:

sha256:663e301d5dfbcc05e76d15e824097808255ba61fb13a322165904d86f3ed9a75

Size

93.73 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2788021278479b83e55d857ee1ee4629fc85a0d0394b4b5184323ee37f2bd1e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1bf4a4f9f8f0572e8aa37d67aa9cdec4a282219908b7eca70e9ce5ba5e40a864
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:3d1b8ce17227d1c60a335023e5b4449c5e8966dcea80f3ae4844554e36857f1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:94c878d6a97a16c2a62e2310942768d18690d5cc6b861a90a642c73c835601ff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:8814238909be6ad5f34dc2b0cfb88df89b5a6daca4a4b172ecd029a2baadc013
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b0d1d1cec0814c5cd5bb638b6c97da3bb172c4783c9b7a5b6e9662cbd0693482
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5318ea7b7819bf4c43028f1404a4fc5ac0ad8b3bb93b19eb9a6f206d67ef5237
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a44612c0d8df3fc45fd8f97a305e000fec2218a53f2f3c7470db89b4fcc4c7a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:19b4b65a4a765e8c8f807e7803e37d593494b281013a4ae8595a95c2b2657ffa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:858e215df308ff78c787efb9dfbd19b4185381daf2b0663bb9d55a8bda546a88
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7d559d8c602d10c87667f55259ea91b358443a043428d2126bea85f448430deb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:81fbd57685489eb23bcccaf5a7ee459ecaf57e0a10c09829c27c2fb0f5c5976d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6a48b535a108bce0051c8317d4ec96f32489091d7788c9adb96f5a6bd76fcd1c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:dff42e102202367b9503589226a5946902f9fd1fdc598cc40aedf50764d6999d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:9f9f10d13e31f3dd504172b2699efe520754783dc76dd3a941339eef41a9cea2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:10230ecc1f12d99d810b50a60d60b0e083b64ddceddabc14ed5b7a940ec411f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:55b4a5e37b6293869b91018d62899af4b56233df1bddd113e89684e0ebb78dfb