Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:f80594f4500ddc22734d38f8184897412c59b3403827849edee3fc8a970e17ab

Manifest digest:

sha256:7b8be101df828a1fc35280acaa70db7a7826f65fcf7ff849759bea8aca14dbae

Size

135.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2a3afb7a9c91d1a6ce9dfbe42aff66226ff8768bea074fa6f0bfcab75b49f062
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d327dd59f724a8c77df10261be29c526c18f65c25271ad426551a5fd4e2cfbb5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:d4d91cae047a7e4a68566b351d46986668182c97e3da9baf66114f7c9ebcbd7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3f383c0e36b3fd4d174c19de89a76df1988187417742bfb5d8dac7918122d7ea
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:4c5f693fa3648dc29110b8263648f12aa599c9bb3ebd006061066e143db9555f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:3e3267031ec2b732d9be5462ff07a5179bef4a0dc52ed9b44cd617f903f5e1b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:cc690baf80dde75c354164217499b88b5bc1c0be1cc3d671bf3dd64e67b85c13
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f0b7885cc7e979a8d3fbde6851509c1e9842b1277ac077ca0a60ebd697e73b5e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ff2be7b5f272ee0fa08551bae9ebe7ba8a320ce092de3977a7dbcc612c4db3c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:cd04659c8afb8974ee94155a318e12afed793d8063a7a270a7d94febd1c28843
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2e663d744005b9dd21e37aba81f9d239ea281eaf3a39299b2d9c7a9cc308df17
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:0a9cc6aba41669e8ad74ae2640da6b980c93f9eadfbb43afed97a4d6a6d036de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:3d4e2de47054dadb4079b4c5c41e44bee0fa03acb063986b2cfecf5764691fd5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:826cc0db162d2ed690788889526cd9fd41bf9915f9a601084954bf000ee653b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:399a2aaa0c7b26f34eeb78f0ff1826cde47a4bf26f813f71f3598d6f5f1d6645
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:493205181f4f0e23d2dfcfe410bc2d313fe8ff95b24d2e1401465cd4f8a19475
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:0fd2cdde1dcab1a008e41e9bbc803eb7ca4d457eddf05006299ee53a1ffd1f69