Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-fips-dev, 3.4.10-alpine3.23-fips-dev

Index digest:

sha256:ac2893d19142fa502b083af8cd268da5b4569ae47e82b7ac724c39cd4f784e0a

Manifest digest:

sha256:c91d3f9f9b29392ac2b16899c3b7c5d93b4d9647db6516a85292988e393a94fb

Size

93.73 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d383112a9228b96fe8cbf987512b1ca2f884de41da361ac7d2f303d120469237
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:848340c11692884c52526d47cb5d85df980ea67fbdc86c6ee5ab1482ba619ea4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6687a8396df22448f4df92da0bdfa1dfd138d9f9079dc34dc8e7e09e221c034d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:9fc088bf591747f7da286154780642af58ab418707921d6372ab9ce983f38874
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:d0534d74f80b5df152aa8049675787b626c9d1077b3fe3a89595e85e02795e09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5b9d0b3b14b64fc843eb27e876cb0abcc34d85c14b433439f8b0d1f15072053d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d0e51907a093c8a68845d5c6e054009abe71f5aec0e2a4997b82b14605dbdeab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ddfa5589e9b2c5b1d82107c69900874666a7499c64bfaf6d38dc673c2d00321d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ff8adeaa9eebbb5861d73f842d3b45727bd74738236254896583fc8062cc07d2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:0d32eddbcd370a2ab3b45499b8123315d7f100eec4bf3fa6dab0c401046fdf94
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6cd37964eb62193a6febaa6c7cd5d43c706eb2cd8c02658c214703c415648814
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:cd89cbbf57255f703ab97ce49ca76d3e8b65734468cc9c7246573fe36295916c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:60591093a944434af562d6320138ea92df24ea9f6a319811bff2055508922c39
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:76087b468414a930bcd278e0dbe4f02d502c0d5f6f98d919f720b711cf93e8b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:cfad45d3c6e6276b00bbfbafbcc205dbc6fbe51d44bbc3fb2969b5088afbdd89
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:8794d808da3a17a7d8f4a917a2ed24ab7cfd3d8ad58c57de656e0f7a88caee2d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:647945b538af4831733f32825bc8a67e80e62b12d7c9909608c71a1d0875d024