Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:12398360453f96cdea00b1a97ee72379670013614efd52c6fb5a5dc0aa0e744b

Manifest digest:

sha256:c6b02021cdb87bd7187aed29f6f8f4d688a17003e51ce266fd0050373f87816e

Size

135.09 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:725366ee071fdff3aec0a5956b51255333e6076ada0fba551dd60d50ac5aa5ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3427fb9355f408ff7d838a0b8dad54cc65ce44dc01e5f298f451c801e3f7cb00
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:d1e5630d5c96ae2a6177ec9d0a2b30f1130ffd3a594e7b85da4a660f93e9a0b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d584725db5b85656ea3729a5d1541b3032c4bf5523ce0edd289899b2f842dfbe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:692f9f93b4e48d19e6ee21542893cb5f0b80537156dff89d83b9bc273b881212
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9833b88bd9fb18b4c8cca49ccd7308e28c694901ccdb5283ec1c36424e8e74a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:9d70890d1bcbef66c8d9c78e5cd588d723cb4095778e95aa962af9fc9a48fee5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:dd7b4aea647120a853fe9f5acd5134d7683aafe3402a0c0ee13412e1b04ae8aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ab1f94e9678d24a6e1dda97d4194c71de1a45baab833eed44fea57fd10bfe4da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5cf2e5c5b9be487f5ad8ce70bcf259d5748f43d6936f469b8bf09543d092dd9b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a855783b032f8f13cb9e5862b51510146d996b331480fda70a9360a6dd8ce492
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ca292337043c572e0aff8e26279598ae6a26dc0983aa276c446b530d49ae2416
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1b13f413212496d58499c50c594bd5c2042edee79a9a6662f44e6b19874fbfff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:61cd1b7456f3fc97cd3d2c2ea05efeecbd33e0403bfd201104a940bd038db58b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:010ebe3febfcbff66fc0e116b6fa9708fa86880f94aa4229baf37729f724cb59
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:37784a64692527ad4cafc91eb58aec671c6b5701c725f3fc66856efbe9238b4b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:412e0d1ceb9f1fc4e4cd3713a7c325327c79916051dfa10fc8a75e7eea61f702