Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:5936d84529c8273b381a9b71363ea1285868bdcc4c342647bb4617263208557b

Manifest digest:

sha256:1831b15050c12cd089149be3c753d99a3febf77f3844e4c1aba3a65acb0533d6

Size

135.09 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ce0066a4a6a4f7c9a740b87694362d5b03a97fc9c03ff0b03e8e45ba5cec42e3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5a84b61683fb520945532271b97e9c62a813926a9ddc6bdc3e7619a669954aa9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:62f8f49a0d8050f22b279ea5b37463ae40e80f721fafd3180e64ebd7dd401c5c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2c40400d2e1c97a1265d3cdc201c0ded992579b958e38ce95913126ccf971ae1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:187dc8f9d693d64b429891095e964bbd1bac37ea225a782a43e223dad683aaf3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0ecf7ad4653462c131ae095aa09bf96c5164e1dc7be6108e0fd9dc3663080446
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ef3207995fd479450c16cfb302ff85984c2045683468e243b66ee80d8b7e4252
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2596eb89c78616e1af965840705793bc2420f421a0ca81611cbddfbffeac2183
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a04620f74d88ef8732d923464ac2a8100172d01b87d5f2b7a5fbda7516c4d004
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:de004243e3da15e1e621933200e92e5b7373e4d19727862878243e44ce11ef74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2c120367fea22748a72777fdc23ed6cf256f4348cc4bf69101008d71602398c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:af22f60810d7c1177c17199f3be8efd52fde322bd891427574ad6a41692b312d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5dc0cd95381a86b2af95ef187c2e0cf4dbe21aafebf80f2bb01ea4447343371c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d124c832783e8b671656bf8fb38dea42da0a2ab661014be85e8f6fbf5810e39d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4fd366cb409dd8e0f6eba4fed8a16cbf8f8047d85e161a2e7eb44a310bff65fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:521b2a5dcbdb84b90b735030893599c10c83feda585bf67bfeb73357c4e799e9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2bf077f1d242b0f0530cd9ebc81cc70ce9f523e92cd958be16c109990d93b9df