Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:763eeb31eea0f4f9d71df9f51b519ca0823c5d7233fabc9e28d42aa3923a30e1

Manifest digest:

sha256:8d0f2c5dacd38a9c1a08c24b2d33f935aa589419a6e8c0ebbdb01a58a37e0c50

Size

135.08 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4e7878ba793e6a5e5c811454ae785b544fcfd1e5d9faf2aa8a4dcca0ebacb0da
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d5943abe6247f180f24d0f20283774c201802c233b9b1a20672e7bf49a9af00d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:a8b6609b2a3876170293b00a14b82460a69f496b43ec5b2e943317867884ace5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3b7aad10d7b4b41e0f3e43a583fc7d3dc69ea2238cd8c5c26731c7b32ced73a0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:6c33256022201b790594f339201d384cc7845ff12f73936a55ebb81a37d48cc0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:98a8b6ea235a8c17a0ff1992e4045a42dc93c6ec341dc7cac9c99b10d604a98a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:12c959e36a72fb7010dd21561583deff3e948bdbc65cd0df99c29483fe79db0c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3ef7c72e4897ab30b3342c75dc2dfe162a29be7b9e440268463ea2fd01d4468d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:9358473424074bdbcafe6e8be86139a85a9bdc0706a5ed616f3dfe22f259004b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:f5c0afd78e27b297c85a04caef7d54e2db5262990aa40afecc69d2025219189c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a364471af00e258127db0aad0c95ebad04c74ff56ff1bd20c160f16dae5bace0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ef8975a2fc5e3583eff87ade5f77d455629d5e3381923c4287b031418913d6f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:cb55e8b0205a6bbc7e27388cb7d885e6667a2e3ebf7d48b0808435d5e298af30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:ba2c574f6e1ac7ba5ec062a3bb62688de16cb099d6da4b1d47acac8b8a16b273
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:845c752fe1f0155d253e7ba4a384ed2b50b1c0f1679f897d8b015978bc051bab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c21da0b07943f55d4f62579bee30df7f1f870015942d43e7a4c9f2b04126b68b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5e3a3aed7047be8c003c4e67dffbb777df15ba9fb1d74035444025875e9c3aab