Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips-dev, 4.0-alpine3.23-fips-dev, 4.0.7-alpine3.23-fips-dev

Index digest:

sha256:316937e6ff224bbce9e27b0d7053b101a18eb59bb45f28edbe31c0d0658a8e5c

Manifest digest:

sha256:60e2b28dea6909aa783b824583042230a43ece9f12f0c1507475d48a69dfba9a

Size

94.51 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
2
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:bc9f2c112125396dc253a035a3a16df2a01703d3ec6acd9216a14638e9122310
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e36d7bd824d11b98a090765ea1df65b6cff4ffd5ff9b07d6771d5d2f1899bbb3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7ccc8e5e5f8f6e47f7127c2654467b162ac43d8402a4f314c728a21c8ca87a22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8bd3f4b983ae33c5682ac6df59eb8511913dce01c9750e8706bdeca74b79a953
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:15f5f713338f6e31751a826bbd0a4cfb39598bee2d9e90766fd5c12841c5418b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1b1c998f056f379932ea2ff1060477b080cee04f9eaf1a39624c661b69389329
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8c743a90c6ad03ef0b3ad10c4f34d90c79f96992001472e168babd113a8f0a57
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4b5a28c56df96656ea5821585239b0282fd6f616a819629c0b2e3a21a7b02d76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f5f23572bd671ab8b998dc8fc99c3b8cf2d9b8aa2eda5c14aae8c9c84dc1673c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d66e8e70eefb7438bdeeb2a5f057a7675888c6e8de5b27291a51839ad7821dae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:4c2816bbf839811afbee1a8612428c7010cf379cd430958124e1304e6d2d415a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e020ec75d9be37f02e786ee3e6dddf068a87db26fe2e04c83c4ee1268d36e2c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:34861435e34901207820b3a9f345517b479f570830c1190879745210667917d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6e09c03398b6e2b1439f759d0bcac14ea9825c3c5ce682f8886d3e99cd4ae067
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c72f62c97872190859f45c6e383509b21273ef980b6030f622cad2b5903b66c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:1782ea51582acac5d8cb9ad02f95c0f75f1cd712f92bd24179eb6e333e9a903e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e0a5d9c117d5950c312793791f847487749f6c97ca3e1ac5d6f1c0799cd39487