Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips, 4.0-alpine3.23-fips, 4.0.7-alpine3.23-fips

Index digest:

sha256:7af77b8806b948fbecc2f5bf1ab2307ecb6f3371b0e70c0245768d3dcf267c2c

Manifest digest:

sha256:2dd5671c6abcc6a21951451a6df2922305628c385df84877a0f7ce1ff53aa31c

Size

11.75 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:220c83c5124d1fb5c2a4e9e84887279f6e8390f1866813542be2d184cfed5af5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:08d0147210eaf397e7f72910ba564ec45744dbcf1b31294d31780d3f415774bf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7ca193aace1f97bceb6d423aa074e465357dc2f145ba211a32ac5623cba5c186
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:74a5e598a9e9beaf75f1895f73b8ae9f00c712b672b1c08b011186658b7a6a78
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:a0a898a778dd8435772f3fbd16c6c33e27736f1e761dfc7f65c93d703a1a2713
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:ac856aa0858613d9a75ba7ded095b41a90e8895194f309d3d976428ac508263c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2ec766423cd446d4cc597cc38ec0bebae0aca73b531f484902da3c4ae8d67eb1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:ecc134f2a2b94a06b92bfa18c8a3b001fe28bf5029d45dd3f66c99368fe580c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5126a62f5ba9c3db7b004d95b0a4a63363c9670982fbad7004ec6ed1cc0f9c7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1f063ab04887b3dbde84c368ebcc56ecfee5ce5d07fdc091bde7f70426f38d24
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:bde41f088c8c56b05b6481ffacc74dda11c0a112ae7d602accc84ee2d3fc465d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:57a56dd39379a6972b897f7da46507ea0a4ec415a6ee77358d479fb976e9d096
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:cbe2292eea737e66743ee7c8be55e40631a43e4860a97a755d7b14bb20c6820a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:dcd11752cb83cec43981e689e456c44a9125ee021876dd71039420e501ae5592
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3143f9fe420216d48db05e0eecb89067a2ccb04aef1508e2ec2e804abba42eea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2a4a36ccc4b0fbd40d826e96ce6bb88bda18005af3220159d2a070789b967a7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:c84e801b71351f08890b92dcf2c2a081f7229ec14d6bfb5e68d0d6186cf5bc34