Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:748afc38954bb2917be9b4e79c19ada30c941b82b7f73c4fda46b07c979031b0

Manifest digest:

sha256:66e378e82dc4d9b9c83a78b998ecd30aeaaa187a8d2b9038066b5d9175a85df3

Size

135.09 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
2
11
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1a0895706014a1c22290dda69c8355c592fe35f42156db9ccadca7fe2b5c2327
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:cf89ea4bb6944c9426803ff8a971dc4c2ec2b91655aad633701816017b66cfb7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:257fdd1154793a17064560d99fd7bdc92c29f67e43e70f50dd2743c1e5561f7e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:63125c1076ae318b9cece27456133b045813a89e927d924f253ec9177164e280
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:5b65a944c9a792f7d6eaa0a6315a9f0a8b44bf2cc6129742cbb6160e70f3a402
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:3ef8fd11df5e58d474591fd731b7ecebfcff7fa71b13e18ffbec7c364b1981c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ee65897914f63f557d41adcad80aa4bbf03be32b6aa7bbb8f73ae65a0dd0d941
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c87fb383be0137e70782bec06df3ca1a8d19437f3cf5d9389bbe19cb8896f123
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1a59e141a2ba7c95899e0c8b64cfab136a73b2e479fd83bc50852dca551ea500
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:4a21c78799be100541251d578849f09d9063621f6f45b82141375723af823b2b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:10707c687ce3c2c373408382c9ce4be03749bfe0cf5f2b54c8fe2406f154c75d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f292a57d50b633a70865fc29801a4d17fa6748a78304b56f3f78c7046a7a9668
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e9b0c35f78a2e9d3b17cc3edcfd8a9908424bfbe509da6bbe26f36f9cf715866
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1288f0642f3f49ab92a32aaae311a9e0140be9b687732fea7f82ad8ce3b163d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:bdb151492f358be7ceace380773ba9cbdc8f3984f7f3d0de8f4fa54ebe7fde9d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c182970dfd56e0716ba3fad35b212ae239ab08e47bcf62351611ac9635c112dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:41a0a89d82df93e6433a89e79fbf2e20e69a131ea664bdc96595000a4bc8ef40