Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:99827ae9205b5ef21241a85bc88f6957460ac30c634362308361dce649f7680a

Manifest digest:

sha256:8b923eb986212f2526ee6f74a452c47ba9d73d0955d6ceef427f192a4ace887e

Size

135.07 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5f0552fd6da22e1c6953fd827e5541d6a43b4fe87e9b19c63d9acbcbce17fc99
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4d3dea83b7f6e80c27811d67b50ef9e158550418cddfd85348eb50c9ff0003a5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:68e46dbb43e66f50da451e1a158e68e92bb409751f399be2df697e55002b68c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c2b7f6c8230343774a6e753f7546e2f7c3507702b20e580fc41f93e9c4f157f0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:986f2c1e3c54c2ad4272b818a051c8567ff468d38ca66765becd82133c4ca411
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:79fe7bc8ffb50e295155bed15ff8108f99a20ce1d02c2ce0a5486de5a8d5e7da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c091de9b336ccd429a312d36ac37aedae5dded9c417bab1c358f749cfc8cdd64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:6e738663db7a77aa3ac7627d00827747df366177a29620088523926e0c5dcaf1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:49e30d9e50fb14743180a055ef06b8dc08675ab79c67e68bd83635eb7ea54f32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6c55afef87d584112408eea7e23f7c51ce26f8d3891a91b5d51d69b1c65b4d40
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b089b67a765225317a473df006dfe963294029b09c98a8a593b3b55850f252ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e5a4af156b5e22360940f50785bd224b52ecea45f6b559678178086bce5a14d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2f83a70b5ffd19fdb6dc82cb6387fcf812deaa89f41d582627a83746442f4eb0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:dfbb5ec0cf5000f265f64491cd8d1f3cc45d20fc3bd3d7ff5d602591173f17ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4b5ba38c68e9061bcfd74dcc29112843bc2f134ca183ac6c5077c1292cc85da1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e5642c988050ff2031e8e93c2eec6445a86a3858448a602f3cf814da6e8e1a3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2983689454a6d7146ccac42d7382c940eb2e10e81b187be8ee269c8c9c4453a4