Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:5f98c586f3a1822264dd24353fe0b0691d3a517c22945dde74235de6d55ba76d

Manifest digest:

sha256:f67d7c0d680f59fa76f0500f293d2e6c5bbba5db7da4b5d66b0f697f5f8aead9

Size

160.48 MB

Last pushed

1 day ago

Vulnerabilities

2
2
4
24
3

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7974b999e20b812dac6412b03f6a399fa6a24a453a0747631f7853fd460b4a8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:7e1ebebb5599eede91aa6f7838060fb7d90f7ee0c2fa3383b4aa644d3ddec9e9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:1b1a6dc8d1bf73db88b1a3c21d3f1bc5988ff8c9ea0a028e1c6e81047653708d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:fb713eeaab793052d38e250bf36ef11631f03df413d6b9d1a57d390e1c1eeb47
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:46625777da02a64d14af1492c0e9db867575c6a1726d761b99f783ef82cfef35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5179f9689b9f70d1675aa2ed3e21c133b8a0366f199d865cf0d24bc0b5016dd0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ac514e765ed2f00b27fc5052442bf405ddcec9999a3bd4df3363f2f178e56884
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:52f79121d8ffdc430fb1c11a6c6c24d0172ddc3e4243ecc2b2b6e3bf7975d0a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ce120f24f1d701026ff69ec11ba63a61bf38f53271976b2df9ad03af48482b4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1d54e03d974aa81f93bacb629b9588b97c188a1640594e86761f7868ace4b6fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3df3d00a959d01f4298242925a4b901cb7a44cd504fed28d2024a224fc40358c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ad15497951065fd7d3c6173ba7461d3e1443faa8bbf145bd0da87bd1268f2c44
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:25440f2f2a0f27f2904da4cf3d5a4bca3ae657f33bd8f9b8e951266e16201ca1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:47e5cec5d9397a0a5853c84eea3e3967743bc0372a1d758a4a15d7f119e16207
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4608f787e4db75be46037cb3f075c30f2a8597a2f3d27b48783755a0d59f7b43
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b5fd1a7df80e02378202a8b78d031126eafa06b712b28b31715a5d830322263c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8ea70645e1a9747f304aff013d09e7bfc080db66b0bbceed015fb409171292c4