Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:1970980e45be8a9411a4e86fc419bc9bc0296018f2da0f96528824b312b7a8be

Manifest digest:

sha256:34ff9efce951cd3076c771dd8f32a887bd2806f6fe3314594a4bbd9c67e63f34

Size

21.07 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:c5a06ce7065e6b49d2378b21ecb0ecd05ff813087efdbf976880426498b034cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8369b086aa46e600d30fd72e084eeb484338b01ac23e3c6c83d4c7205235684d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:428f2c079951229cd74c01d462aec197ecee33affdbb62ac7a1d22b7703b508f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a9c02a827e55d73ff078c7b4977b2e4c6f6eeb9fec2f654beff8c89817f9389a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:569ff6c698718b29b326298611ab662e67bbd00dff9f262527cf06c34eb33d78
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:659294deb86b0f1d3574361ff6873ec794ddeb7565b61b99584c234ecd2eb35b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a68e76b4cb74cf5ff7c7586fc09491c92ae217d54b40b51594434e3c557e5799
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:0206f0e09f1515a05f7e1b7d664963c41c31600847139bffb67db44fceba1140
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:397ad8c57fa0d9412d38f9dd6d79217cb5bb0dcee2519fc0d07d1c30b8441e83
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:29c8459e5144ad58713ba16230061cc4b5c54ce1396e8bd9e02738740baa7041
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ab11e79f492181cdbceadc332523ddcd3c7c6aa0131959f261559ef472358622
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3371e8ae41b3bebba37433aceb30f9db6148625e641680a279294aab98dee192
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:a126f4c29201b93b60fffa43a3a14181c32eeea3b9122f33834cc26360155acf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:501412329cf6132095364fb89746fe38556bfb84082b307a3dd8eba7de514816
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:b218f15bbfdd98130a28b8d9ffa47a5675c3cb870aa03594ab05470314db25da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:037f86cc4f9a3fbd5e683406fec5ad366419d539610c6b1f7b61e628b9ec157c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ed709db780d252cfdb4e22f50f6bc6685698e7260b6f51811e35f10dec4dec4c