Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:4381274221bb026f825b280ad5a0183a22b769a359936b3a432ead41c1e44a7f

Manifest digest:

sha256:02a2c845fda20f0c270d590c15385c5c473e4801bc4efcd35775c7dc8ace7413

Size

135.09 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:f12f340653cf0acafe7c42e70eed00947efc366a6470ae8edf17a240144bf03c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a6c1ca5d671fb33576cb932dd8b8d4820d9e2957dab9ac901861fcb0fb1710c1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:57478bdf151840c4b186d14f7d39a171db1a02dcbd7927496ef87130615f4a5b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8021c0877d0f70bc6d5fd7cb76ede3075322f443bedd3fcd0c1cf1932e9c0dee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:834a9b5dbb95dbcd0cada34782144469162afb69e4ec95a4afcdc6721beae76f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1a5866b309d0c856a65aca51b4ff415d1ba7852db56c80bf47ac8ab2acc4d836
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:47f236cc7250569f6a1691ff5065adafc0c93fa0bfb2de16e0fe8d592dbb82c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a0f3c1c92c3efa83ab8581ce9d7245baecd6a6f32e24c5c44de8f21decc1ee5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e2ee7ae77dea29ad2651ae62c2b0b14b902b11fd213e0fa9d50e3b8202fab2c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d078525bd55bac430213532984966bd045e377778a5ce6e79b0068c64b16ec44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:048ecdff852ad441d1048d621bf70ad09747c43f09a53230b84f704d0b33ec0f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:0f4d2d35bc398dc63209593dc65ee61690db75a04a66fb285d2e788a47cff4a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:7b581ed8dad9ed85f201d4329872d908c6984caf1ee3692a62ba42948ef4a388
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:57b6ab3a515873b94d8212210ca80cbfcd443c64340473af22d233cbc7eeb9f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c3ef720fb012f9a6cd212d3cc7d73b50a0b6e256b2a0365817018fc43e5d9231
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:a403fa37f50056b56d3ae1aaca88175469b5217dce29145fc2eb0d00b126b571
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ddb2f9611f7348ba1031e5ccf8c842adb72459425486d6e92af938958da4b434