Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:71bdb53bec6c38a30dd34a6120b3fbbfdae71866c0f6549cdc3d196578dadcc1

Manifest digest:

sha256:deeea0aee052047b5b81745796f869e0f109ec054435b7cd4e2005a792ee2e6f

Size

21.07 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:9769d3fbf436f75eb57b314a6d492434ce5797e8ffb08112ec453aac6b2a83ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:aa42169c5a2aed79cacbba350f442d96579ede89f4eb3007ba295e291e6c7659
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:424e713a85d076eb5cf419425c6e2bbea5c3d7ae87161821b7a521090efcfdeb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0565c65fdf2fcfdb341665474e5e71028bd06d777143f49c03369e8df1c39467
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:377886cd3e70cfcdff723d29a9c53bd7495c4c3a43f531a652a8e3ed3da15b7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a9acca9abc19d46e4f8e601417dd466c6016968fc0cb099a2d5487d7093d7db2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e3a315e884147f95c587ab49511348a5bdf0ca63d274bea2ac1bbffdc201071a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:90e44d58706b0c299b61efbf99a6290dd997f14afac7806ae7a903ae47bdbb94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1da95d9746d5a7b0a303b38d3f4016a043eb505dfffa689eacaa40f50003797d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:aa22300988a7d0b401ff86ee48de59598d70a9ae4e9d33c53fcfa508cb316164
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6b5212492eb8b52d357dd2d893072ac9d5c6170b0f08a96c30bd227c42165422
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:45f435742b67b77ee455644d3c434c4030930df527e7570cbd350f4ad6d4ae19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:c65bb35b283f9acc30d0d4d5770ffb8f9834fbec9c1ae7ea7d3c53c9766d398c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6380eb92b58e550cf65bbcf2c6726d58fff247c7003417d709f754fe18902b36
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7531e06dfaec0007df7bfb001904b994491c309758e802a8910e98e56f726011
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:90f9c111b03850585ba6b15fadbcf681457f12f2ad82f99951040ddbbeb40f64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:06e8ebf5e2bccdca09bdc71af06e3270281b8218ed12c1a908fdb6ae5d76bd03