Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:30e8b447a2a01abb34fee3c486f8b012528ac63da12a0425a73114535c0d67aa

Manifest digest:

sha256:36a403a91f3f59ea1435f4d30cea8dbf581149ceca8f640a659916b05f0026d5

Size

135.08 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7484b21fd56333b17b27bc4397626d98e0d9bab92a2d1eedb8cfda68143f50f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f94f50de0b19baf2ef49b8440d2f95d0b7d40d3233a3582a7d57c79505880695
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7394063ca466e49a771f3c2f2587fd5eeabef6fce8087c9ad7e27f62590d809b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b3219d77a1ff2bcd26d385d1c282fb034dd06099736327cec506b098fea736ec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:9f614f4c19ca7cf247ce7dce104a7fefe4ac5f439cd6a611a5c95141afa6ce37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e9a6cc4ecd578b5cc0c8234e0ecf652d1a9b22c1458b439def7cdb0215fb73ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d89f5620a1620d3acd7856f19ee7fbce2a3a0349d58f89c6b65e41bb3e6e3170
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:af6405fe346ad8db04df12cea78b1dad228683c193836fabbac6324b3a86aa57
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3e4862ac9962546ddbfd64aae54af85895a3d84c157bac33c0954b38aea65013
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:4afe3af328aa8f94e112fc0f48ff07243f4a22675b544cdd5c4fae636dd03aa4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:604ba5f222693334cbb90ee8ec904fb4ca87b88122357b2a20f4adbfcd12b6cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ab3f6754479597a52f04cc8144b400a489fbb54c57a64316a5efdf2197cc65d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b9993b7cdbe2b82ae8778c03bb894d1b19b6ae049728d0319baa541abc89c38c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4f0033954d77f1370d640a8af827ef62c9d141945bff10b0cce5818a2bf3b21b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c69dcd8371f82ecc77322ba6da9392e795bc0e6c13ec7f77a4e2b05ad7569b16
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:89f81fa1cc07f676634ba1f3e807314f25cbaa638907315d679e8d86e0ac1b50