Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:a62d1082450676a2a9248d5c5aa8ed270dbb7701015566450b73b987e2d1b86b

Manifest digest:

sha256:49016a174d8912c8af2598890aa359a6f79ee90aba99df7773234d2eb4c81169

Size

50.11 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:cf6aee09d4ab396a7bb160ed51f61c8f2b494f96e10bfb05208c9ee764ca336d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5022593049c536a378b60fa68de167ae3f89581adcace216c3a577ebe45e0878
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0621dbe228d676a2b327dc120cfdaa87838808d49609f7e7711f5b142839805b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:33c81292dcfa30d01fb242225d34f4ac7467de1aa04c9175a7f2a8690c1640e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:63b20ed712d27b84c06387839cbd8d475aefd192dd97875a1d44b309a92893a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c420dd10a0833855f34facdbe4254ed951c9c971b8470369723fc068586f31d7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:9ec077db73a2e47089423177e9efdb7ad41a2c480c6ffa7ed8a88d8aaaee3b61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:6556320c6a94e12e98362fd249adf90017723aba3ee5172b950188c34667605b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:12975970f68a9c5f503a2bc13f761b9152e0ba665919f5f10bc8661e3044145a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c4a5493bdd1e264d0395c3334c7ea80a680e8a6e594a96b263a893e86d5a2b69
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ccca39d58dfaa0bce7d3b375f81dd808f4a500c2ab577e9bbc0004e724a6f8de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c436be355e452ec64639db407c710784ab6a6711bb04f90ec0c0613a317ef3b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5e6e69174d6daebb3eab93261d0742f34b60f17b1063b37eada092b80c91c1f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:29f81da41f32e372106db8f5dcb18d046c2dc6b63829b3cc881b6e5b58307924
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:710af4c14b9b93870554807d892c263331161319a967385d855b624db29e7e4d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2a2ef2142677089d0f2b683c001eef6fa48add5e55d669ff6bea15cb62332933
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9c621e866ae228b6697ba58772770e23da7fec0aeb4eb5d638e6f99d9e1cdae7