Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.11-debian-fips, 3.4.11-debian13-fips, 3.4.11-fips

Index digest:

sha256:a028673ae687106e4dd954b76842c64b8654c320e574645d841f70e5e0e9d806

Manifest digest:

sha256:1d3c3021cc49da795ba401ef9b6664ed6737b4645a762283dcac2666f00af108

Size

21.06 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:042efd472fcf44c0990de94beb3c2e99ec8eb4721fe051dd36dd7da22da22ea1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:557bb0b4498b75451bf03fe54b4bba6f37ec3150e8f19249ed9fa776d10a0a89
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:229c28fc2d7014ea09ed634b8bcd712d7921104faf154f81a478543ac3ddcada
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:e796d44f35bc60c202e57c018063f8df080c802eb1044b8cc61552afe6b79ab6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:05cd46b9ffba255dbd54505548cb8f0cb3416cbc416a4b72db192643f270b9ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:72585708e8cf545186c1edcfb1e94a58e212b65985937dac137cb1904a496b94
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5c770c09e01ecaecb7daeb09244e8ece60bfbc35b3cccc87505db5ed9ab5ee59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7b533f600a7cd6296bce86379af1af058b0aebfb032400648b7b2622122290b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e95f679b81b6f1d1381c327aa2ce282596bfb979580695ee7a2cad7d7ab5def0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ad458de7cbbf6cce53173394ef00a292302a35aa6a559ad5bc516f4ffbfe9f90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:bfd8a0c35deee7e94e780330dca92a8844955204b3dba560b60318744fea8cb9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e5c7e7b5263073f3750c1ab1b41bfe4d78e8b4fc52798a778bff12fdf3c78c1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:699152a1091d62916ebad7d4eb3dbe13bdde6995e34e3446f18afc8ba5379f9e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c7122c72400f6f9cb30b48033a49a368314a41a9493544da8487b556f86a6060
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a6d0d8b60fda07c38555ec68e58a396b9f218003e281047f5828d2a0440229e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:cf758b8629d24eda552bc304746e7081cbe6991935fd3b1fd1700d8cb8e7fe86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:facdf1748bf47a826b9355040f1172b01e535f1fc143a41390ce1a4e7450571d