Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:f8aa2ee7f55bbddd454c22529955e1f39ab278f1c2032375525917717b8fd8e6

Manifest digest:

sha256:a379cbb67b8e639f9a5887a9ac2edf10dee7055b2b1dadbbd129ed0eacb2aa93

Size

21.03 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:784b68ee0ad060202c9fb152d7df8c974a6b130716a66a12dbb878102e3b02f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:42ef96f203f7026ee0373a99593d02786c9d08b8d6332dda361a2ba95a3c14f1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:94d3254261b196d7c9ef3d0c914557e97b70969b134d1ea3d2bc9568a637b706
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:fa6d7fcd5e007452645ac20fad97514b1dd961da0df4687e663b6ebf33f72830
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:7affa8584872703da25976fc2b8d79a6c54f0715c18027ccb97a0e4ec992f9f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:7a8e89ca0b1922ae53101124fef2475d29925c1854ba010d04079fb674a0500d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:26c1d8a5d8cb7064a57bca30283c8dcc703f52f12b9bd83b7bcf894940c74d2a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:d21034ef75abf02bc1495d67b8f47ed059107631fb1f0080d83a6cafdd25024e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:382f88c839144a7b1c647f04ae4cfa4051359888e3d755f68b0b77c2ebeca852
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5ab790ac3a53fe488b11c4ebb92262993ad977bae704a2b85ccce24eb12ca5a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e7b7ee8d2d9e354e7e2f34f58f18b6fdc0ba0a59c88050e11f1ad736d67fba0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:db2c39e64441437bd5df8fb949ad3dd8d629da86a7a8a2ec6e02c3c8ffcd256b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bedda1834d77ca0f03dce0d9724da238178e82810ee7f1eff7bd85345a8c86f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7ff47bf96b3e106af4dc3812dd61a0da79446940bb905fcb8a9cd78ad26b2523
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:db79ae0e9df5feee0e5a62eddcc07f07d38b7cff99255ea1eeb69ddbe775e93a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f2c32ac1baae19c0ab8c53e186a95ccda1cba01167188005ddf3c6a57b982868
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e98355fa15bf07130275d1ff474904acb9c8aee101ecef3b8d39faecc1837fe1