Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:1f99dd8fc413480cbbefb5d76e8032dc8a6036138f6608db11bedd2abd320a3e

Manifest digest:

sha256:26c78c8c9e30a6188fee5cf36881b9dfff655ab61b3305d19b3abe7ba47957cb

Size

135.07 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3a7e483c41d4e144df75880330ea04e1d60217ca4c0be95ad9ae49c55acee113
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0f01c8e0dab117d0397b49821bcbfbc05546cb51825ca0e13e1fd6105a497fd6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:1dc1efa740002a91185dc0cd3944db5810832e885b22965f6c6fd68d7b024524
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8adaed9fc95c248c87aab0664ac4f33afc46b5c54a9b43d6652187d724ed592d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:58f2409f8e19c2f8118465575a5e363b127d5e59f7b5268c03fe2942aaebbcda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a2a1d132262169610f1dbbde26b04de79266c4dedc23afdcc9db206b732c7da2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:7a7970fe70d4b6f14b6ca107a0606e87a6a2b4533cdd5d3fac2446f887eb1add
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:d27d676de6119853572f655f2779838de68023eb836072f38755772034f17f9b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5b969f8414a6fb910b1feafe9440a8508d770e804715ca61d49495fbaa3e6ef1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a802dcd243c4cefb65a8245618f517910371429445cbe2716604444ece839744
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e9d31d30fa43fa48e0bffdd9acfd368774e86f94b7d249fd228bb25e09bf34dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8fba89e0f7fa7d83085b288c6a414350ffb1e350af71a0abfe9cf090fc6308fd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:18c611c31b1b34df2507def3ad65469cc9d34985771538128bfbe71c57117afc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:90befd83d3b0dcded79344ed001bff5ba0de1fe14860d875358fc64dabbf750b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e09ee52a5ced7df60720b2cb6a7a9035da9fe54d4710e8b9faa73b44e25f048e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:49e5feff4950a383c74db15fe6a5034f1d4a5aece7e96faf9416f5396f634c5e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:824cd5c62875f8ef669649e51029971f0767907b5ede5bf28783b58276ec83d5