Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:b36f1612a7e95164c405a7dd5be48da50c8d6e0a0167ae268dc5c74f6c35147d

Manifest digest:

sha256:fa0caee258a23955a7384c13016627b9312f42f1ace86eed8f079d52d722e2f8

Size

21.03 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ce8c8763a2e68566ff09d7d8aa597def5280ced9a1444e37c14645415ed94116
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:dcc30cba3c2c267ed7c55f66c66d934e006af4f81857bc877f9adfdd73c036ed
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:70b6c68d73cd90015b6445f1262b5b03dc2c673bfdff18052323b73f86ba0f83
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:052affbe6d196712a66f27b3b0cad259e445a3a431a6bcb168cc36915c3c2aa8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:0b2222c90fcdbc8475722dc761c60a93f223570b1fb155d8d1a548d2c6a5a9b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0f21b2d23ef468cfd7d80d9fb5a8233f557cedd509176f5ac1083610cb00d090
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e555cf82b4027ed8cb6950e3f241d755d91e19fe36c1570ecd52274949cfa2d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:05531d614ba8ca314979ee92576a3e31cf0a1efad38b3eb1a6615c82802822dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:69020b9a8d202e575c3764304f1482026f06163f9cdee5202ac587ffee6ea4c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b56e9d2327d3a6c53431a98b84ac14c7301bc3320068538d9138bb6ed92ea39c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e057e631206f441210f816907734a7f5757e7c04fb525c33c127a2dd452feb23
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:0d1e943a90e787e7afd84847932e98d6eaa37308d199ba64f5bd590dad97ec15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:54798abf0cf1a5edfe854dadbe422804d41a066fe2288d3e9733ff9c201e0d6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a278f47b053e06c919ff8f77162b2bcc9286535d461354afce3d701af57181ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5af8f44fd97e24264b77bbeab34bf74bb42e34c36ecb0e3610b4d91d124b71ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:96992f1abb25585a814c50193dd44fc068251fcf0cca287973fc0122d669ad6f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:77736816adfe32218ddd2d7b6ce2504fd3d6318d2351ab5c6b5f50ecba7c1a5b