Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-fips-dev, 3.4.10-alpine3.23-fips-dev

Index digest:

sha256:cb5a5d766849604a162e423ffa3c67464902a56b3a52f9ccaa6e1747467b3a83

Manifest digest:

sha256:9e10ac8c445b48d613a070ca35d5d66b458b9ef88a0a4b6d9343fa0a20096ab4

Size

93.72 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8497a8d46626516049b4b4359e62dfda854b7d48da212300d991b367918be15a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:2d6ad00708ac13a7dc91c5025abf3584408278ea567894b10d5dfc80a9ede01d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ab7e7228f09dd57bf370483afdfddd2ab412ea3f511daefa1cb10bbfa31b8ef5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a7fc5b877c84b8289995bde455d304bab507e3ee5e465f23ac122b4dac444ee4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:800aa75a6a731cfdd249a620325a694368e86acdef35f5c262fd27090cbc6365
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:635a99997f335b3f9ca2b89c5ba32cb1524242c70f3fdf90ef10e9f2f43af78e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:01849748d9d36f8cceb89e14fcc5f9e236b090b4bb98abd134955990f3dd90ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c7978eb491a87688c8c8670a77ae226f89330222b3946d7ace080b0c1db45d38
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:be2a327b6ec11b673407219317bef3f978e85e0a941d4ef42805b757db60dfc8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9a0bf42088c2c426d3c9f16ff79f25fdf2f76600646d166a37546c53a8c9abcb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6c2661b4f9337e7549a1402bec769a918fed9e90dd5be019052a93b222a4d6e2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:69a3baefe98c399f887df4b0a71641863f0d21d6aaedb4ad75c469fd41d4c433
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:080210459c34864aebc97e5d4263946d44648183144ae5c4a7e578cd292fd9de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f80a071c3a12399de513999b78d1b57a771ffeffef9c9809fb6b616609c8cfee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:30ce9681a183054d46025e41eea9df65c4382419209f82e08e1c0ec586c1f394
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:06a087a20e4ce5aa54a88e836b890454f0a53d5f0213f34285aea24a3e1170e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c34e0c8078b82eb5a839b323b400264a51e2f43e0ea30d2c818ce6fe6df3df72