Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:45362576c4a70b56eb5ecc93ad70407c3d95d5ba463b6d3bdfdde22a8d6109b1

Manifest digest:

sha256:ab1585c23c741c3b8df0fcbc77b6056d5f076df2f257764e75584de60c84d599

Size

135.08 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
3
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ecc128a842f7c297732f0efa470b2621c27fc33c10719a668d68ce228790cca1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c2e898cb289a93dba947e39fe980205720531ec43806dea619f3fd4ad5679e45
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:1ab5d33e3955558ce9d2e0f12d2f66275bf01191cf9258cf997f58f9261e499f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:bdc9c309caf78b759a9cbea9207f532644e587b64a97d7884bdbc496d262322c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3d8fa5f883c2e28e0b803e698d045470dedac8589e6c0b76ef223a4f37f130d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5d53a4a935df4c76bbf3d9d7cd5d2d34a535833aa468193ab5201a1a892bdc7d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:774b3c2a53f5a9d9ce1674e33503fce1c0484eca22531ed5ec7d6830abd66b3e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:24ac31c9ea162a5e04a8354072d735582f43cb266b8269bea49c23c66b22d0cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5ecbac39fd8a6c4076e7479456d90203cec6c2bc05e596993aca7160f38f7c02
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a26ea67c496a82653649efb9b43432ca43291c0af0733db313c18ecf45360310
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8c4801c92f4e1b165a0a4b4703af7f9af98d2e1e9cd94c46f0faf78cd6871e22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8e3d908a645f2fc03187f29640a96ebc3d3b62d94d72e11d8bf41ac1186a215b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:997e4b79c258f86ed750cdde6f2f13cac7348ff7b61efd30072d9e85d09c9859
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d1f7d27fc08c4efcb8568893637bdfb27dceab5d617d82cfe00b39949fde261b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:bd96983b4e02283d89da59a1a975c6d9d5b8972fa67d84dab0548efe56439e44
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:5cf68c8cc6b0158eb09538d4fcc95ec1a3284529d00203f15df7e0af7c3abe52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:22efe9d8412dc5ccd1b059bc60af348d808f6b9af91ac3c56a10082eb902c24d