Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:66300de8d843e7dd1a2733af88b2ce97cef4641b43e240d78892118a52c5ff63

Manifest digest:

sha256:7d5675eb2080537a58ce7016ad7973eba1e36d3f9a29f89d0a57e68e2ae8118e

Size

135.09 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ab0f623f7ba156c3952a5cff35a3a41465c21fe93be24522267a5ab1cb2ad8b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ba5a62f19a29bafb9b886e8eeb991ac501bc7633c5d5e8dd906ffcd19b36a958
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:11985b02acf8e93b07c1cd849f2f8bee214dc6e6faff3ce72a0e01b73175b6d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:084058e425d0c7d74e10cfde064e05f41b217a5da06815f78bbd52928f95b8fd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:9f0305b387cf615b07c1df847d4fc58b81b80b1c4bd49a91132850d122cb0c6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f1d0bb104922435106504133b10bd40b1133b1de482929f3f7f76859353cb262
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:595550be7a9cba91aacf4feba9efb561928eee126862ceb15f659002d438c4ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:64c27155fb3786097c681d88bfdede15e1182c8b56e03aba1af344f544d2912a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:adeb33ae9e59808382916e9c8976cc9fb0e1a789eb0f665b73fd587d9a9c56f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b48a73f6b888a7549cea20acfe372eb80ba1f96ebe54b14bd98a0daaf8aa5d2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3befd7702d18f627139b619f969ad263b5a23c2708cc9ef276435629df3efd43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:cc0ba5077cec513424db1bc039b9816701f6628dcaa70ede20d53aed92bef01f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:7e46cca5e3df2af77f0d53a08f49c7d55ebf0a09932f0c6c8678d9e3ef1e381d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2b1e90c9f73790f09aede87374ccaa255c79b0360e1f647b8beb7615128cd49b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ae7013193029ef5329c49e01f823dd9ad1cd208ed4d5d9a439a2627d654008e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ee6ab8250bbe932a7d1ae6694375a1d1e39832e549b0cadca31abd0575330fb4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:a35a009f982106ff6aa4ef4a2d4d8eaa480c144ec45781a4ce8140ef71b18ea6