Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-fips-dev, 3.4.10-alpine3.23-fips-dev

Index digest:

sha256:3e356cb6b99a15a2a42c5fe3b0504ba07bc3e74994641381ab2d142fb6d21eff

Manifest digest:

sha256:a9dce1d7eae8155190e1f152a419c3410f041945fc34324e3ed1bbb56ea78710

Size

93.73 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4c8e4beca02216e8e09447dc4ad159ae51ec5ff2ed3cf36aac66bb2d2c15c134
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4695afe193923465d3079c0e1f710a01cba1c3007ed4e0954af47f776d16b441
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:3d73b59cbf1aa640f6daa670dff40f4d564dd3d956d71afcc627346915fbdac2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f09a1b34ece53fa25cfdc3aa463e1ca25d10476560246b06eb07cb2ac7dc8049
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:483df89e58610308bdadedec0adf41d4cc423b420cc3af1151e6346b22c71b24
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:62baa5c8ce14a8b2bb962aaf3553378e52e3d055f50fbd3d548504b533d48cac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:28d9b4daf2093dbec4ebf4933236722db3f6930d8cdafec0f8205d1f085c59c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8dac53e7afdc394497c152f6cf10f2178f38f9ddd621f4701e49ef1e8402dbef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1ad1f81d41b14b6870351f33026f20075022a66e086146973014804fba538c3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e43721d90630f6bc8637260a39b71ac8bc208343d7f664de0c6b72981272826f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:107bc8cb63a7c75e3ca28619f9ee657d797ad0952ee3076bc5792e86f0e9f15a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:63a7e87d984317c98e099d3c412754695f47376535a41e14f31f3764ea5cc190
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:17c491680ee984e506cc85a69caf8d3fdebe33c9e2b0553fbceba5eca52b8765
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:9053eb2a55ab5697dc42e3b79cbf8cd246bfcd5e4a34d30cc2a9c7db79b3ad53
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d7540dee5499305d22f7cfb93eeb07e5659111193ef7bfb334d4fb134e5c23bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:9e1f05c8ba1d28480c37e0ace4a9d3917dd35ce123abd19f3d503c473c46a018
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2b035a65d9aa7dd3bef846673e68cd3b472fa66dd35de4d2579ab39d44ad835e