Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:8f8dcf018a50ff29d9515ef962adcef3439477d5c64fa09b4f31f813d31c7941

Manifest digest:

sha256:86a2c7cc8c358dd44a04901c2f47a40cace819e70e37eadcaaf7c4c1f24e36c0

Size

50.11 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
1
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ba179b785c3818d69adf3d9a3bd7a3b9ebc37b5307bc12c30c7d3864b01bef51
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:60e75015d3579784a3826dad34c09890e019a2dec888d1d4986b12fb18c1d7d0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6f76f8c0f331f779ae435ba688993b4b1773a265ebbf0911a421eb5204910889
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c9e85a4ead9b79a4a56962dd536e38940177fbd67e70376f037b38c0ee31ee1f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:4b9b9600428715bc4aa586fced5b06fe69574765d1b0c0056f11ca03c14ae066
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f76cb47a5665b8acdaeeff0c3ad2271375a000e98a9a837ee42ecfcf8cdfe045
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:b852ff7f4c955ea2dab6e0af7aa066be5b3b32a58aecdacd7660bf461cfa587d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8acd6e8fe1f09199f28103074e807182a65aa993f396887c1eb737d9f9561055
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:23254baa73e93f4447130ec7f17920424e08fa520a8a7c993c6a9b0382131ff8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d9445771c08f519cff1d71816321c9ddd7405a5abe868e78b839ea9dee2d9528
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:59a12620cb49e7dd35e6b3fab1e80cd8af97f701b8970f477f81086fc8bd5c29
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:4d63938192ab704de4bb3ca20b82c3c852c1ee0dabd685f6dc9d592fe8391d92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6927d571e6f1d2cacff8295324a195de3d40a79c29fc22f13a06d47451ddaf12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:55be42bf91fa0826c7a501d073a44e3a7288ffc3dac3680256f97ee7bb42bc4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4ff4786a75accb6ba231d77aad7188f3dfdad08cde1d94d62277fd59e5504573
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f6927118f3e6d8a0df104730cae730976c1835c739a968e9561190bb2040a273
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7a55370df46addf5b956126fb226af2664c6135c005f9ca627831b99f5975a1a