Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:7f42c20ca39c7f171b19724d3212a6d674fc909dc4f3550d7cb20ad26ccd3f42

Manifest digest:

sha256:f3d5f282a2dd1ef2d7469f7328684fb5473f5d15590a54da5a63d101181de56e

Size

135.08 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:fc4eecedcaf3613d0034267ca4dcf44036d50b9da490d6ab47ded0aeeb589358
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9318ef76f4eef9d7ca72b93c97b923e2a6a5d2416a8c358ac31e930ec831c5a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:63bb859a1c53cf78eb5ee6fc0b937e2010585145fd3ab31c37b4ce429fcf0984
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:65658c02b78fd310e6c30913da00c172024d79f7bb46038b2148bdbe9153707d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:bd4eed42ecea6cd4e852a7a7afc82df14fb76bb005ff683fbb4cdd889876f3d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:902cba925035b213970054e06ddf2ec340224346a3c2483d4e43a0941ffd12c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4668d0b4a6ca80325b2d0cc6815dbaac29121d98d0f65f8e31c18fd1ab7327b5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:17ee19da421d78650700566e2d30857411525c06bada3c6cbd0a00e8d4d345d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:748a2be9500c59d278b5a43c79ad735ad583f1b5b041e49309b1a2724a942755
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b213af96c1e22129424560fac58f9c1fd77d7b40605fa29e2809cf2e9d49edb6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1c58038ad8585b76abfb4be7a621aa6660f6a24235228288733f6012b5ba72bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ca665d9dac04a21dbf59cecbb2feb8d631dc8bc65266e46b25be88ea49b0c514
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1088cbcf0e5deeb17460e21232aea29320c0dfdca6e5175800b974500efb892c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d43155e05c053600dbaff44d4faaf9d8550923b858cd9ad7341dfb65a5d87512
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:dc4cd739846d11d9ab17e43c34172301fb0960cf5667657586b1cbe8e854dcbe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c5e5f9f026cb0f73bfc101e4317a46e982eccc23b1ef01c131c798f0d9a060c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2cce272db2dd932ee5b70a3099174affd8bde4d916179849d492f415158e3cb7