Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips-dev, 4.0-alpine3.23-fips-dev, 4.0.7-alpine3.23-fips-dev

Index digest:

sha256:dcee1180ee164ba770864084ff3a127a82a8cee42d4fb8f14081114bb1d510be

Manifest digest:

sha256:8602bde1fa03dcc3d2fa08b8d5cfc2942545818879b84eb9d23451edbfaa1ee9

Size

94.52 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7ccdf4b6bbb4eeef3638a9d6b667ae835a57af7e5b9d126d36edc4cc4bf5495a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:68cce8bc742ab7fba016c73e4f17754eab495a4418609fe7dc7887f8962f8e4c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:152b23c5ab4be32bd0495fb3bb51a6b54de16a321639b6837a1d451e5aed1ba5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:ce9a16c0852d12f4f653233eaaef752ff4bf429976184f4d56b68149e39388a4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:98ef5b11ccfb5625d629128e79b17277dd97aaef03bca07e66a5f4014bab9820
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fc9d9b8f598f3792d117762b95d90b9ade70d53f7b627696785a9d5f2d891c61
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e15893577d0aac18dd1dab710f0b02f325b414bdcdd1bd142bb944f16d426ae7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:20b99260305c8f7eb67012b7fba595089977e22c8b01cfd7c76568cacff0edd4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:27559c194fe6ded6c834c0749f24fc5891ec77e7b77843cd0743adaa6b8f4ab7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5776bc477f968e8a74c8a1084c5af830109d34e05c6fb33d8933900a019bee56
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f42f25618d52409256c6714115a49a4b4984559675b0846809fa909f70177470
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a50eddbf4ac423b0e1cde9ae640f9fb62822770b5eda1786fa2e21f6c1ec8fb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8dcbf47ed602f9b844083836132abe72793407794d6ef94f46824b111feb6a6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2f9821c1a26b55b5e5cb240644b44c6ccc94e7e20aedc849a72bfd22c4138196
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a3f6373290a5f9e1c1d5ba11a9c16b7aa9693fe7a94abd09b765267162dbb30b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:9fd9a0cdf355e870a502ff532757c718571e0b1e498338b51451391991be891e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7867c92717b8914b7b5571a4ef4a31ffc3216201288b8e2ef98af0a67bc35da4