Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:058be839009cac932f4e9b5d3bc61e7cf0c14768f61d77125bb355ebe60c4456

Manifest digest:

sha256:cf6baf91086c3d1f3a1e0836fe25d6d77a4f4fe0830e2ae4381713ac14cb6eed

Size

135.09 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:06814ec5650e6eb11f6dc37536695d0103aa651082eb7e7f54033b82389ec28c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:55698f9f39cddb72a14d56a18252513cf639d54198c6ed264d7e545d55e31998
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:d3e925094755c037ec8f99718182ab01ddd3530d4519e19b9e6f5dd75489e1f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f843b0590272c081efa6a944c7b7a559aba3915b08d4929cd800cc2d6cc41f7f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:78f0c143183bda57c26c924cb7892796da60f34c6c768772d9e91720a6b88c3c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d217617e330197ee49ce5a1357afa582630a16e6a93a75cb3ac41c0c85cbb1e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2a3feba3a127d63d183f796ed85ec008c951fa15ca46e71a4d84f08e1ea6e641
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:005a8cb241c7cfd45bbeadea1fbba5a9bec2fae1003b7e98ce532bea2aedee5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ee91f2a6fb84fa909d33f926fe25cc48022b84a3cb684afdbd48864fd3a31a1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7c0bffb4264735f608cb7872b9762a200c1063495fb8f5f0fd650c24732b8be4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f2c2e983d98986e8a5659598e40b3da945aa766e49953cab45cb3a17f1686914
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:18100b81a0f45ead612d6c0c8892b93bed0b72e3c1de695a44e3d13e05dc3983
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d8e3ed5ffafd2a4a2000f1af63ee3cc5a0c68d75f96c0280d2a19601668584b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:af1ed104cb9609f45527edaf74169b122a7cc6255ec5d20ddf2cd4609305d33f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:aa9a15d1a1ccd0ac2014946f424321d0a7c5f936c5a6753792b8ebaa31025ef3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:8ab1cd7efe8410434e88afb7e1de900644d0efdc45a616c649e6fe85323fa1cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b3f229d807f5f7b2d67bcdaa84c50665ca2b61716b485aeac1bb6f8bf4b90c63