Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:5aa03bb74458823a19809719382aa63dad725cdf3cea706de363a7189ddcb91a

Manifest digest:

sha256:013b42b6a22f60f76194f1950aa066395e4a21e512ddcf29d173c05eb2f54da6

Size

135.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ce94d95ad2b90f91d40cc8952741abace3cdd925052922b7f6dfe1864460ead1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e0f80f4ea0dc6c0187d449af407d457dac82f27ff947a703542e69a6bc84136e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:79f575d83c83c63981e237179c7a59ef5cb8a476a368fdff8f59ae6b34cf8b6f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c96d559222e578745b1fd68cf103a4e7a578ee64023f729922dc97464c78505b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:496bfc5f7723f9ae0c0f491e31ff1f171964d61a20611af3b18dc1fead87708b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:065ce373df69bfebafd9bcdf36d58fde9bf08016343a90a607af26a6659f478a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:32b26e6124f12dca20a0f20cba1b3cf11635739a8b7f07412fad1f4a5be8f828
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:fea83899efce992a56e385cfd51a26088065b059dc8376aaec41c651fe5a810e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e2b9c402b8290a4a185e5d104ae7e9d286f1e678de64576aa04fa8439242b93a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:638ddfcc0c47f82da1c1620c187ab4e159205bc55e557f09b9530f328643adc9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0bfdf3e30ee88f16fa09dfcff94fd62a5ed8d50ed577b491c7cd567ae0fd092f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:419b2f560b0f05f59169060337b267f691fab20c05dab0d037b93fe3bc498c52
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ec0b1eaa24a7b754d5c5c92f832be5e1f083526a9cdb6f439e9d1104c57ca1af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:5ee18f94698149b388b3d29df8eb1d44d813695d75b169d1c4ad5cec0489d933
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4f9d07d037ac435d30b9e5d392bd23001d4c3953221460ae70f28a9f0ed9f284
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:3c6ea2eebac8392b7864843f7e2a834bf04e64c2a40f01ebae2dcc4948da2931
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ca5afb3e4fdc8793a0297cadf247576bafe9a3b67dca97262dbfb406e7655629