Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:0073f7fe5a02ae2b70c1591496bcce9306c01e8ac3551f7cab852fa34c94faa2

Manifest digest:

sha256:1ffd4db2f58d20685d19965448a90756369c1c00351883b564a34646636292e1

Size

135.08 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:30fd041345075b04d8e5cad890b76fcd05dd5a278d10b4f3621b460c8a0c894b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:2b72ecefce80c384f1c1b3a6590299bddfa360e2b9260c3c9bb3e617c499ff33
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ef683add372ed90004e3e9e9286e034e89cd8acd9ead2ffcb41456d0e6a5e3fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:603dfe5349ecdd2b1981af20a954de7d1eb16692a7c77349169688b6ab5cafb4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:182ffcaced090e855918739ce7aa52c91da5987ee53b6bd7858d6b81e7630042
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:021fbefad39039d02b280ea67513c1b7c85ce382157e7579be8f89b5b5d1bf09
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:b1288b8e7cfd78ae681cc2e4f921c89d28441ed872c708254c3dbb3db86686c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:bba832706723eef1748d3f3d3b2bf12c86709fb82c2aede5658498a02a4948be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8e2d78fb59552e3b2736119baac17efdbd148409b6b021f721ffbcb68a0d7c44
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:02db20d80eb944f48b770c71055603632399222189c936b7c172dca4ac8cceaf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:29a1cb5734cd0e8f7489768b82a962bff134995294b099e238835be42a126867
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6cf71a3c2e704d5b7eea2d2f12cfaeedddbf810dfee0b5f3a3b084f5ec857145
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:21e3508e293aeba8c03723e191b7cc438f19059f5b63f8cbb91f795fc0e9d4ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c540de7ba5af427fd65f5166302acdae2b197a198a282878ef1fcb06e53805f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2a4b8f74848ec38bf9c23e066c402f33d04e59301f53d2ecdcdd0a0e96bc0a99
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c5bf27544230950939252f27e968e9f0b853099f672946d6b14bcc45e38e8d2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:46832ab7195c43e17689f19bd2d1d5f29d2747cc77fd7c2e1f50af84176d4dda