Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:8755e2ef53afb80257556cb709436959c5dfaf184fd21b29de0fda53ae9d63d7

Manifest digest:

sha256:b5ccc2f87b768ae46a03c0eedbd7847a2bb4da2dedc7c74769705739073353b3

Size

135.08 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:bbc1dfed19817bfcc7ad57daccdac41cbbea006257d79e7dd1e5b5c456efa2a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:064b6a7610980a7bcd8b0deed97d8a318bb13e02980cffd32a7ceb76387c5cc0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:cb9c3b792728ebf297a00f5b51a78a2075ec54c26fc846f50bf74fc792d06cd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7d2b00ee59ad6f4d1f99eb3a5977d1e076964dfc8942c3cd3d7c626ffe847505
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:56038ce2b1b0c2a56f14ed7a0b61f19b7f12f7be891475c04d836013056a15b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5c0177ecc00e3d741886a228ae3ef3ec190a4557b19ba03c3972fef38104abe6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5e4ba15a3f33154c728ce62b6cf9b4f186431d2070be34b54ee75c1d090211c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1cdc206cb7677059790d347bb9020c813facee188f631ec70c633fd21ae91681
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d5313e601c9b0e8d429a48b146a706396208eeae5ff23871a95dfa7578f47c40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:339adb5deb7f1097ece4a9ff187322c952a1d3b2a22b62f695dd241b53c8b718
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:33f49f29879a7a554c6ca52d964e0da41bbc3083e98194b3ea25e33706551913
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e956202b94e33f7ceab3cb6c3756e85d8495da5e1d569e6ccacf10d73230cdfd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:14d87fc4a17d77ffb83c247e73b6b214587551fd5d443fa63a11c42ad7efd601
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:477701366d8594a8ed794af8d261fb0e9e69bc95a680730801e6347f2e537dc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:11de3d2eb307e500e9572e23974379c246062ab0e1a9cc62fa25cac32124d595
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e623862f7d2e1e8653245e9cd1c4e7579366f22acff717c1e40cb4c7149dc391
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:531f02b4fc466fa3801b2f66622735743a9b8098f01ea45e069a999ebac165ee