Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.11-debian-fips-dev, 3.4.11-debian13-fips-dev, 3.4.11-fips-dev

Index digest:

sha256:f1e360d37a4d28a19c55f4243b2a037f3d60f4946554d344de6fe0b83b8503cb

Manifest digest:

sha256:f76e6aa6fda35392fc04861653082f224c7c096773667dd60cc129800c0f1686

Size

135.10 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0a07d9f02f602d61bc5507a4a73d10cfa3f49ed468b5a77eeed2c14fe39882e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d6752ac5c13f5bdac94acff9c286bb50039b5d83a8d92a1bc1172a803635379f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:00cf1491b57377f72e0227909fffd3101aed3252d74e9bd18fe25acc90e150f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:dae80087a7860100ae4eb86cab985eacaa356ca5d2ea24eecceb24f3f91ed624
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:dd4f2be40d39aadea67f1ac95140e676182b910b1ca8e13af00e2112173961b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f42445a589df230829f97d526307953cff215db5d5fd4b04798a1ccec8f3fec7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:87902ab8b4e47b92945f15fb77d4661146c9e4770843b90975377005aca5ce26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1107708595460eb3f7d9ff87aff52f700b4a22eaa332a0092dd8948629e99ee0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:964d90a58a369dd742a922c4533c9bf56d8305f37766fed93ec83a0541f990bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:bc81ec71ab6c95f7bef4ac4b997e58bef7e2ebb59de0618ff136a121da01485a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b14f2b337db2af2d53efad9cc9b3c9c85fd7d8e97d229c2965cc22154129b7bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5164e4d6f26e524920611c9baf6bec6d74d87680045915e31c0e2b4c80452126
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4e8bc926817e7a1f99da46255767536864a98ee898417f183395ce69d8b4d70b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:497b7341f49e5c41f6d68939b533ca903126a4f4c5d6fbc964c95ff17d5e3c8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:090f921bfe3c49160aafd97c69785c6c51d0ea276f2f661e65e369bb107231d7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:096d6d004ecedb5c0df4debb7a30f893f946e1a03cf5cb40b2b11b5dc970bb00
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:1d914a0423172ba65a2e9c6d531afe78be8f4b91e5bf35ab5885379595f29bec