Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:db60bbb0f2a02724effe7772898fdcbed48db3605bece96641430f2ddd743e7a

Manifest digest:

sha256:64c7b2da9e3c886991ed13765abb13e7a61cca273d1660fb15f9b9509098ea72

Size

21.07 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:80bd28574f1f1831b45765cbfe41582a54969bef6345da981b82cbdbf42084ff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1ea87508e526ef4fd8903e96889d6763cee8b20b4ac94de1b70ed5aeae22e8ac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0494d68dc8113cdb529d2a59b70623af05ab045c452d2448fc5ab3aaab8d7a55
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6c1398a50937175dbe40ae4c17cc91438f2ed26215e090e556e953d424a27034
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:99324c8970dd590cebecefa1ade7c65cc95c97976d2010aac7bc25c7d88aa27d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0567f499b12a2953c020c91349da477a4f518213efdc6413aba1eed2f922f622
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:67dde33d5edc2c8ae4e3a2b37626672acb8896d79f0ec6159709ca7f23ddf190
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:d401c52e2ba095db2fa8fa274b39fadcbfc08ca6aefe4289829c99fb222485d4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:cb295dd3822f0a2761a37f381c1058c41d3ae263b9820ef7921f6ee64c730d93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ff1250a74833b89473c2534f392e533ecc82fb8333fddf640881cc6af708494f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4a930972cae2c64743c10aedd26e4ec539e23e387ba619fe78515f396b5a0a13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:943a8c1afc2370a429f9a8db9cc922e563722cb5102a28fd1e93608995078d50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:03071db76daee1ff6d8a5012c5b33662d2da12eb11fe2624225a75c61d3da3bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:438554611f67e2570539d80922adc176c08d855887620fb82a9e3d00f727adf0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ceae69685032bf8b2353904aea631998b70050aad254faa5cd658a77cb12f3ec
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:059870cd0377be4dd5628fb9f816b5e6728bcf34e417e03b2ee2291f4b1c11ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:95b0cc22713757031c6e236c25c68d52359e35f0b688fe082b8c55c460034471