dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev
sha256:7f9250fe1d6886a504ffeaec1ff84c3142bc1151594c9549c6d13d22132a8abe
Manifest digest:sha256:360c320bd84645018cbdc56922685f4de111503af86dbd07355b1751bcd5a55b
Size
137.45 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:08a2b472e3c057351a80e8f95c10576473cb4235291316bf3bc2b65faf8802f8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:77d3686ccd1eda376a4364f62ad1b15b4d7126661d9a2ef533225c76dfd77482 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:617d2e4ac242e8a6f5aa6b95f97fc0726a2270e8c4629bbf78c008e987b0fae8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:a1c3874d61520bfe4dd8f27317b9f6e75a41a706aceef8e3603aa2a981cc837f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:76cad5295e5f7a450bc3b8df6b0faae78fac36cde83703fec239f47ff2900f8b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:861b238b07f3d30ffbdf5f498035fce37e97eea862992883b0c2324faef58789 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:f60c9d4532657240a6595b2ac499c89fcfdf94ce9959a39c1d40707e33f245df |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:227c0667984a8fb76ab4cc64db61a14d6471d67717f1cf0d125f9671e87b2d42 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:25df718decbb711fc436f9bcfa8266397cc2de8ec68be6f827eb0ad683f43b37 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:86a94abac927a77ed4fb86e50c90b4d815ce40109cfd10e4604e15c7dde62f0c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:ba937d04c684fe3aaa4357d127089c868a3626b8a2740c5e2468c9a76b3395c0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:310881e8ba45dcc6a1bf5015894cbea8da7dc4ccc99478e4673b530b8c667fca |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:dc9d62c01ebbc123448d80e082adbf26465472c605ac8990f87fad7fcfaef8be |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:f62543fef346d5bd7ff2a19ab6bed9a73715c4efe4566136b91491e33d69ce31 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:8e0d994c879580e410a913f39de05114ada0950e625ff9bab478fc7f6787361e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:60ede2956b844ca1aea53aaf7c4530653dea29debefcb8ff028b763406bcab87 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:917f3fa67d7fd3353d2ce400ed22f2bba426be480ef363161eff4fc260bb509a |