Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev

Index digest:

sha256:707aef6c9f706d7f963c8bd43392111c27ed961126052808ae0511f2d1f14409

Manifest digest:

sha256:3a216d48bfb1668092860eb1b8e3c1c8a378cb577951740a57b6015bd6d641b5

Size

137.44 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:72ded273b44173cc51b5a12a829e6ae18e04a7e0a7c5750da110d6d75ffdd526
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8bdcc10235733e5f48658e4c90a902da2ab1b2645f87f3e2bda2aae3a0a84b84
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:007334e90539e00c92c61f0a6aeb57f33e837ce31bac87814969c9ffdfba7090
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5400a0cb7fbd65deceb28709508b13a41157b4e831172c51d579b19eac6429e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:55f5e9e144051c9931ea67814c29fd88b0ce4c880d4080fc1c59cfc46e89bccc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5363b458616abbaadba202a23a32f6b2008641a630d39d3935311a6b09258419
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:6d586cab847470a13752e4fb509b7e7a8dad773185ca8fcd4f186286cbfcd4b5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:79face282ef18fe6777f13c87779b541b154c0efc7137a3f1b0df3a6e19b1bee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d8a0e95e0495d7cbaa9886ffc7e8327300d050e25b3841429be3b34dc37a5850
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8b0222bba65e73864497a0d4e23a2586b1dbb838f00f5b0f05903e1fb5b8971d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:555168dc8fe528dcd2f0519d8da1cdfb82195ffd32ae980c10a253b2b99d1e7f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:434a55b6b9bb8d5fbf4abfff0593677b965873cf202c5e96f74aa41cf3909f78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:407d002ad3f2463336294d2b1e601169fd278c63414a6a893fcc1cbafc1be459
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8ab35010f78fa3c71046abc568439ac41d5cbfdcb7ae13daac8a2a91bda53c6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:980f7a899873a50e9f03b6b86e7ffa8d50a7a9f1fc47ef8b3d45d8273851f51e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:373f769721e95b5d1e5ed0abfded94c3ac063130e0e91cd65a7b54b183d0ec3d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:50f651c00f96f4609a595eebafb4d9fad3c31170e4b10ffe75d15ef5db51a601