Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.4-alpine3.23-fips-dev, 3.4.10-alpine3.23-fips-dev

Index digest:

sha256:4f689ff9cafd7b7a8c93f166f2b023b568c5f9622706c2842e8c5c8e45d948b8

Manifest digest:

sha256:2b37348da40e19e5f91adeb1a47e44e50b2d80c80d805770480e109eb4051bc4

Size

93.71 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4b369c411b7d813794e84cf13e506fc9f3d09510f367211d4859664cd95c1244
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8893642c4f7898290c422770cffd43e04f6d0754c5df066a6c3e5d3ab3e56ecb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:829c9012a02a85e17486276793627bd835cfffac331bc19b888e49cd1be3b686
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8b737182a698147d85f7d27d7cc76f1120008110d5ad705445f1e6ee5600e993
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:58591f706589f99a2b237815d3d4773cd149ffb53d61f8394c19e3acf3fbdbed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:ed5d5ec5d499ab91963d0378d5bfcdef566b21857fbe64e97b6a2a24cf654f3c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:63115f97cd66d3a811f10c63dbb4ca4c6bf774b59a371fef13aa5c1bde6b14e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f5855d3db4b76dca49b8b7991d66f3ffdf6d03767c02ddae98ce4b9331e1ccb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b625e9aec7e8323e1d56fa8197e176c89dbdeeb9586c0878abc6df9ee76e0e36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8a615ea6391dff1f04ffa47f39fa03b7ebb13487dc1fbca55ef073cec0164089
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6f7f1ec4970b1775f5ce05f3e50f68c40e48f0721c0013bdb7570d663253e378
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f3f976c78c287f6b4bf11daecd8db74295bbefc6bb7bf5e7e5142285186189c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:fbc4fc780b91560616ae89f39ad763e6b5e437d69c9704781f8eea7f4dabd3f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f3703d802283ea57b9eb2d49cdfb97a13aa0e11eef2cf2cf395ddd83ef5d205a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:07c096966559d877311fbd7e59346d28ead93f4075c4c4df4c3781fd682359e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f04b5ebf08a79507600c3135ccf7a5b67ff0e3370379c82ab4d647265a6fdd8a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6678620691ee3da22fb0c903bafa337d8ec81c4500cbe96322d87d9c44f7676f