Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:35ffb120893fdcf0a4b18c7807e657c081a8c36c24b68fb2f45efbbaea841adc

Manifest digest:

sha256:1fe36a600dc746d19257d9da3cf231cf3df8340e2068ab61341c0c80e11da3b3

Size

135.08 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:850d66109355ddf5b0b7f440d4b3e12da4e77000ce485c97d66a33052d8e5c3d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3202b85e94259fe902f404b82d6603a4058f95be881ce486bc53e3aa100fabdd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:4cac71786ee4196ce5bc0f6ea3e1d26e1c5ce396a8c1c869e0a400e3d8175aab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8beb3adfcd16af86ce25a2c02d0d4bd0c210ddb85215328c757bd7794b43b532
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3a532465c82a7d7d36bb9486ac80930813c01fffeebee29274d37e9db9cdf5da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d1c96527ec53dd6001d0f11f3631950bd88b83de6190b7edad1d0a7982c30b80
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:580cbca8726a85143e8eba890b0ac9a26558e379deb035657ceac92618e14a99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:0b5cbdbe304eba3ca38ff911bd57aa6e27e59ac481d0155c11b24aa51bccbde9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a0b6c330be2a2ab5b38b515f6c5050572fcd2bc37003128518bf3ce7d2948438
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:90740902a4814ab19722d7b541096471d223e509efa9e7582aa59981d719745f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a082ad7a93d444901e85136ecc4da08846a337b9f9c5c2085825350992ad4537
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:36052bc38c7697f6026c79ae6163963a3744ec0c3472a39eccdf39b233e920cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:76215e7e693a9e0cfbc6c9b72ee9cfb14f3c4c74c8f5b3f92fd38dac472aa08d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:536744305d9872b7309cbfef1c57c1351845e609673f9b6c0a85071b8a5dad38
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f860aac7c1d4ee1ad5e51f78de8203b4c7ceb2fa23d8f628c6af9d83e94a8b94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:51314c662df9b26f5d45279264bdf4d826f6f5fd4476edb6466750f9ca4de321
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9be4cbd1412e8f93645590a0cd47ad9fc00d9442b572c2ecc88d50c9b2384a97