Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:9436bcf41a9c633aa708c2a4f06fbc72e4520f3f233c97f82b160dfcd12f9e43

Manifest digest:

sha256:1185218b888fb8610f23f2b1aeb2de6f94ffb744e572368e29b6f1cf5da71597

Size

135.07 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:09c0090543f311411e6bc232a8e035a57be23d7c8cb789a5965036f6f64bbd63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:3d1c6df9a6719f97305be63516d8331724e968f82928535a1a86a9fd85095cce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:bd9ae172aaf2d4a5c9772c0440761ef05758d84708fb928309d75b1608802ceb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6ec79ce9e5adf0649ef1fbd89f213e1844c520cd0711aef59eb1cc8dce94b367
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:cb648fb320262f51f2dd5ed6d556d93ba02ac96339005672dbe1c24f2161ba5a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4324cd5d83266bcd44bbcdbb53ab66ecbc835744bbba0f0d266e3cbb8a524e95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:381ed0723bb016e58d1c10a8eb06e380c97bedac8a6254b4f87f7e522e4e0da4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:52ee58e808df79d26fdb661d14461eaf72a83ca6e8a9fe8b5226d1fb7991513e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:125dac38ea154b44a6777c0cb6a1a7572e2ea5d07acdaa42284db6a07c5c94be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:f535b9ee2d329e116750439c051929293c33cfbb6134d64c2f0395f33f7c87da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:05690a4bcfd914756852fefa0b8d803ab2cbc277e9b5e5b60d61b47bcd6c6a25
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:75cfe2737d98cf6c3c4a543a1e4dd7fdd108635592f2ac0d2ea7345e021b6a7d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:a9548bac957ed01483955c86c266a976d00a3dc6ad7c85aa70440ed66bdbc4d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f3941ec62c8b096f0a3d2a14d3bddcb66378653aadce8184b5d5905c428b778e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e92cdcc80c495850a667fca8337df77f0ed5c1a2e62650bdfeacd9558179b2e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2c1d8e2162d0a4d741283190db318d4201631a157a6f4231be07173e99416226
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:49c142cc6373d29c8ff77f15f219659d1794bb369c82614c88ac621bb21b9a4a