dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev
sha256:49d3c5230e6cec83096a1f7c585cbc3d76646a6d20c6d2bc1fefd18c8db3ce1e
Manifest digest:sha256:64e5b6c1e7fb36dc1d5c70a60789e921e3c5ec034c0773e0524ab13aae937187
Size
137.44 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:73444a892c62a65d19b722f28918d5ad6ec8cb20496e6a0c02165942b66f74b3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:9f28be24c425b0d0773ce856d5e7944eb688697da8160cb0c6a73cf755d0cc63 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:3b0af115a5730f483cfa6c6c67f15515cd7df2dc35d1eca452ec471e2a4fc2c3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:7de34d7f0b7f7d47355050a30d60c5c24a188696eb460ec1189fd07026bad581 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:94acbcc098182b5e04e49cf9e67e61bca66bd97c0b979ebbcee6119dcb95b31f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:a045dc13239b29ef979a3ce870364dc22c4520f9bcf364cb40042eb6aee8be04 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:b8fb5a5fbd599087a512a07c74bd351f5f85f992aac504e0225bcb1c1b537cd3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:875dbab0ba9ca029e12b796f61201f6de2a8724d4bbc4314ad39a5da8c58f716 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:3975d779c055e8bd6c86a6aec3eb0b069ba45aad1e5a38b2998d26d7037c157d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:8c65c825af5c2c90ab7c6cef8df71c4fd3ef82ed08b0a38cb2b912e7b6325de3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:3a70746f21ab63dc30c3d394cff04a702258774e6416657bad6256c262f13fc5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:7a055d9f37b16e68df8ff35a293e6bd2a025d8a3a95b20b0d22b996838732dd5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:979c5dc77e53a32256779de4b12a6620371a18bd3be4309f1268c5597bf763d8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:2cce24a7b86d6c1d98c3d6a3dda315a0e0373bea5d96b3f5eb35ca217be0f18d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:68c24ba169db71f86030af2dd7c9d1e371d4ccc33304c0422de851273d17cfb2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:d679677cc86924f33803d5ff7a5d135ea7795ccc005c9711b1c163b7b95129a7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:7d81573b4a22d49ecea09550b3a20d43e2fa693d28a69acfbc59e670fd939565 |