Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:38a6c87bfbd3621c48d482497747cc73c6513cf913d74ad0a37dab066462d9f9

Manifest digest:

sha256:49ef49014d46a1c7ebdcd7742d65f41df1758ec23a3c757bb123bcc350b14f93

Size

135.08 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7dac869adb79ab78069bbdd95de01f8e9fcfe3dd2d8211cf1e42760d95801cea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:192f9799aaed2fce48c123e3c2f2c7096dacb69272187e70249c429527f69912
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:660c35ffbf3550e2406daa00857dc0019ab67a7a05897f96f148e2da045a7887
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:84f906e68157adf30c3fc049398bb4638dbcbc3a58d0772d51365e822f36c612
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:6b5abd20b8490d7e5eb147647a5820518a62bfd9c1686dd6a3a6b3b45c388c99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a6a268b2bec976d5263ffc181d8871ea3789863fe7c0eee937c8ecef41cef62e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:28dbe72f7ed80e7b83275e51734a11f7b97f811f6e3f4976c366c1e57fc42a27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:87d3d54882bceda558dbdd9758d915288fcfde1e744be861d624dfc38b57f2ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4b4a9e9e701979f22c5fe5b44c3e418c937c96925399a2fe760b92de84d3619b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:690aef431a1d8642a0a2bc1610178a6f5bd8edad458e6ac7415821c2e1c69c0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8686c4c281cc3ddc39509ed225fab237f578a4c5e4cc07c30944120cd80602e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:fdca2a5a9a2628f6d8435c0205b7fffbacea5dd09e33476718053121dc92d38c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ed0cdf12b138036d58e4b7765bce8b6314a8891f64334bf9b683401924608676
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a7b79e3b9bb9acff58f9257a2417d2c68cffa96da1d5182f9a59f5663148b1b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3a69087e4a4f214b0091d9963d2551de32699ea7e3997e5b9e44848dcde590cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:68c1ff4958db767f277804dc4724a49151bc238f5e12d11bb027bfcbf70be9ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:30aa137d6348bda1e043701efca6b4f618c77eb069353a954bcf09f97608dfde