Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:2ee765732cdde100a42510d92619078ce4ca58885eea79eb5312723e0509bb70

Manifest digest:

sha256:8d6cabd24a329dba36aa9e3995869a3dff90ca95432f3dd21615af05fb45b12d

Size

21.07 MB

Last pushed

14 hours ago

Vulnerabilities

0
2
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1675a4d1a1c9fef07723a91ab75d3e8e16752197b1f81daa03e65fe1c433d6e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ff6317829203bdad8bb92e98e32e00079e2a689ada4238c3f4b473f92fc54433
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7ad541bf413f4210df0e311f1b86de66d90cc2b8db7fe201ccbd3923da434354
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:952996907359948ba8dd13772430bebf340719a47761adee528e3a17d107034a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:c75ead53385c99fd9e24bfcfa1e882b9deb53663352bee8f9b36c40e4b5a6cb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:11b7257b6ec6607fad4e252cb5c093681b6f9d671addaf6f52102d8b2e18ede3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f4ba4bde3c6e1efb21a7bca8df83eb20cb4309c866f0eb1157686190189bc264
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:21d9f6c227436a65ecc65e5d230d8859a245d0f980fe2ca5e9675d70819dca8a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:abd980531a6e5257225a1a6bf82b1ae85880dbf470d2c0bb751acdf684da857a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ebed66fe2a5ce4ac23d3a07921b04361d70eee0072a9154982874870783cccce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:81dcc480c0ffaf7a4f15c346cbb6839bb8b0f7e27ce0cb5fcae1334a09e3d335
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:64c431bd987764b77bc58d7fed95e232d4911aef891157d86f46d79153e93b52
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d7398c15604805d2b91192ca5c2ea1275dd116e7c2dac68c982685eaef4141dd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0d016eb9294797303f74c1ebcb04e97ec4cf5c1ad33aed0ab6244f44291bc051
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3634fb740cf069aa3eaab6f4917f8fd1912b2d891e7d2ea2620d2ed001ccb5e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b4138cdfb7e791e4703e8562cc52782d3429fc3f17fa177c0806e6bdbac6c359
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:bb790073ef4a428866b806a9652de9b8d7c8f75bc2781ec3e23b18feb757e6a2