Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:7e9f06f51125acf3b51ded5572d89d4f24663711b899feba4ea5dffd3a281007

Manifest digest:

sha256:1a35de939f83b78afa874624453f84f337c6ec0655b32ad9a2afab7c26c9d86b

Size

21.07 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b8bfed291f991298153869b5e1dc3652f958afc606a158b526ab9deab6340ddb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0ce12c417fddb08548b7335c564073aa2c24065caaba86be220e0a9c1b070018
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6858a1fae21fb20e6305ce61c1c42ceab575dc261c934e654ddb1b9c2349b8db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8cbf8a6e3c01a6b2922de100a40b46c97050e0962346e1ca17d876c67552673f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:b91adb93aac7976b66b52064869ab2fa4af83adccba165fbf86566fa3ce4c52f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:554f24bbf10de666a8947e0f07ca47917c4fb0fba8ba455d0d434321bb57cb97
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a24748e5cda1523b5f1e87f4d18abe02478403cac931fb9d701476b8631b99db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:e49f700ffac431ad97620dcdc34b47e28726f53ca3c068c3dd38e504c85385ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1720f636ebbf5d9a9daf28cdf177b4eb23856114f3585ef73107a51294c4aad1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7fc3c7e592311bed7eccc5603b0db4c81bb918562fe587c36fd17433c303d166
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a403d5c6c6604269b71357750baec77eeb345886a9bfd9ee0d58474c12c8cc33
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ddd4a028eca646ba39ee76506fe51af1a998aee4dd3db37c80c3ca940f4ba62c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4abcf58f985570fda6afa08c261f83dc6ce4babbde846833f805295afd0ce9e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1609b67dd6e9f027cae00d23c359665949b4c5bbc80d832e5eed5e3a40ffc2d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:8b2b7ae4ee8f36cce855548959fc564e07aef9bc618c255064d2a419d3cfd038
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:6422d28b94c4306cb8744d262e4219d063b0ec197cc838395ffe12abe77d7165
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:dc832f0994ed53858834d246f0afc68e892f4c25c7aa6f766a5a84fbf36b9d64