Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:c1125c1b5fd0594700f60361bf39cea11538c822b7f43ef460127de375ea0668

Manifest digest:

sha256:d2dbdf49c123b9f6e88f4894b047188750e8c00fa887615207749c70c84307fb

Size

21.07 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:6898f64313d09f038d8bbcb24a4ce0bade60e6648a41fbeeb75fae15452d967e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d9e361d57ed1ba5a89cba1b6bdf3e90dc477def994eb103a5d81441da72f12a3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:c9c48c9543615cd23108bc2870d8c69ab5323ac84059b83a2c829c9a54f38bac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d7a68baabfcdd97e9968d3c287764b29bdd379c5a57a5add68a7b66e857bd228
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:14ab67761e5ad31ee588ec51fcb505a1894c76c9c9d624f82e263bff6af2e0bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f9c67459fe1dfbd8c65f7b3c552f10889e33eec9289740e4ff69a969ee72dde9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e67547a1cb6bc256e3df9b249791ae384c0ac520a0060b73c486ea8be1db3b5b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:afb3180e6a2c983cf46b99bc702cb9cf14f03b7e680990ffdfd6a3cbbdeaa50a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4649c86aa2e8e1a5a31b4ebef213bbe2414d6d369fd63a84a170c11d0ff24bab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8c52945148272f83213259f7303c9d73dda84e1106f45882941165354d38de37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0f9dfaa0711afc44e060c4453045267acbc44d2092228fa28cf0a1dc15bddf90
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a2562ce268c1ca51c66e8e5aa99032b0cc8ac9f16d6652cb3a7e232facc51268
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8e5732bba710a6deecb4ebd501c3af932e7c947e6de1c3a80938dd07dcbd4879
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:80c590255ba453b82800129da641d34e70389cdaa90b1038c7c772f7922faa25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3e39bf2f2e278eae26eadfc1c6e5a9457147b4a4a88919b021b0098aea2c240b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b913875301f944c4c2b34d02956e6716b62b8e73628d6f2664e8379cb0d9e9d0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:352c0f156b1c9c042bcd5d65e67aa2f400335ccf560ed39d33f9295b5f25d118