Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:745fd0dc774d88c927d469831cb1e8179dc1e00237385eade9c41130fb64096b

Manifest digest:

sha256:c0933e99133db96b6bbd346ba2b12a3c27889fd83503433c5a99971b9d0b27ca

Size

21.03 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2cd5e45ce7a968f5e24fadb81e403e6ac3e055b2c220049dbecc1501e0670bef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d24607b617bb39de225a58dd7bd670132c2c0c2823d2533951b875800160931f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:137b1da94cd76b4fcc6e7f2b9f1f54588ce4f21738d6a072f3445d3a4262102d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8900dabea976f71b3be9486533905dc9dd11e1b917313734e42c7012d84b19f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:832d8af9c5d0365bc6fd24c0f450234dec08678e65480e537ee15aff379b9813
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8164af9f0dc5787d0c17553f87c5ef8de3afa556ecdf206e1073d7c5abe48f29
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:28d5c01142c18e85ad7e32fcb560ed32938a379a3f380217ef1fad3b226e2042
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:04f734dacb2051317adc4548c0c1fe1a91d68ea3573486b8ab359017725c4d00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f068089e01161c27bd7802c02eb0ad1adbf0d047adf2af0204d7777192985efb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7e35085b967f8a1c58f31f028b64a8dc2dafb425842234ea9298abbadfc92ffe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:446a2efd8540bfaa8843434605b3bb855d7adeca88ea06977ea1b252da5d5d85
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e338253fbd266ca801709463aa059f06d583dd9ffc0d93a428e3761858f7b3fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:76b6dba2bdce204eed4adbefd13990a4cffc2662c42c215d533d109c92baff76
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:ed7f9505fe61eeb179bb3279c4a25f194037d848dac4d97276a773ae93a45329
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3954c48cadcef7d69af10fe0307b507f2b925dda4dd62ee770498cd8e534ed54
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:47d8f3b597daf59f9c1df76341cdc127fd189220d69b311cf2964ace04825740
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f3b496052598328acbb08c1dcd883f56405571c1907cafacea5911687f4c2ee6