Ruby

dhi.io/ruby

Ruby 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.10-debian-fips-dev, 3.4.10-debian13-fips-dev, 3.4.10-fips-dev

Index digest:

sha256:0a91766cdd137fd383282e512d5c8d28ec7ab48b80ffea94755266e371f4db76

Manifest digest:

sha256:b5d3eebe4c273a34102aeee6d93c57161de24d77311f2f799025d55bbce05264

Size

160.51 MB

Last pushed

16 hours ago

Vulnerabilities

2
3
4
25
6

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ce003f78541953365e492195343b06d2151269ef1be477ca9c1fa8d6b7354c33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c11e9ce54bb0173c9e5f4ef51b6408b1a0f8ace2b640fe17e6eb7056f074130c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:def70f138449c8171587f8267055d77808c13c78635b1516a1c7c095131d9088
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:aabd46921aed830f621bbddd0477ae0968e442fa8d00557b2280fec0ed374ef5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:2e892782c2ac351679f20ed02d7e2e4752a16ab3d4aea14019631fe434ce535c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:987abfc9bc8614f8adf14979f64ed9abce3a9cc3292bd3321cf9dd7af4db6e20
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:6b63954ef7d00f57337f06ec9024d99a8fb1986eb4aa4d7d5eccb6809bcd59fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a9cf39be02d0058536ba0be872cf0d6dc4c83d2a5bc876f988124d4dfc90d14d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:2db00f026aaca4f77add6154e525e55d75cea7264356b612943adc87bd360385
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:90ad012594cfe8a9765072f97d208e9e63992527af82e56fe39b46fc9c3b6f3e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:d227d3ec8115f7e791cb51bff2dd071798f3d16a1ca875a33aea02736b433180
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:46ae807d6ed34cefe081aef92f9879cde45b1778501533abae7f7391fda05778
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:606c0651d9209c8dd3c6cab589bc36f895b05e746470a3f0cb8dca6b6a731e04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d0df65bb1a66879161965ebeeb22a7e42fd43aa219c31a28a5e5b325d9ad51f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:6e7effe4442642dc79002ed75ada007b9c67aca327c63a9ef895c0bb22a8461d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:eb18234e74835bf96e4f2663203aaedcfff50027529adabe56f5d748e8baa1dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8d9f288e83494bc1c7e4289bc98183d653ba2c9b3ce9313c1f3c8f4625e54e99