Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev

Index digest:

sha256:49d3c5230e6cec83096a1f7c585cbc3d76646a6d20c6d2bc1fefd18c8db3ce1e

Manifest digest:

sha256:64e5b6c1e7fb36dc1d5c70a60789e921e3c5ec034c0773e0524ab13aae937187

Size

137.44 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:73444a892c62a65d19b722f28918d5ad6ec8cb20496e6a0c02165942b66f74b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9f28be24c425b0d0773ce856d5e7944eb688697da8160cb0c6a73cf755d0cc63
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:3b0af115a5730f483cfa6c6c67f15515cd7df2dc35d1eca452ec471e2a4fc2c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7de34d7f0b7f7d47355050a30d60c5c24a188696eb460ec1189fd07026bad581
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:94acbcc098182b5e04e49cf9e67e61bca66bd97c0b979ebbcee6119dcb95b31f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a045dc13239b29ef979a3ce870364dc22c4520f9bcf364cb40042eb6aee8be04
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:b8fb5a5fbd599087a512a07c74bd351f5f85f992aac504e0225bcb1c1b537cd3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:875dbab0ba9ca029e12b796f61201f6de2a8724d4bbc4314ad39a5da8c58f716
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3975d779c055e8bd6c86a6aec3eb0b069ba45aad1e5a38b2998d26d7037c157d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8c65c825af5c2c90ab7c6cef8df71c4fd3ef82ed08b0a38cb2b912e7b6325de3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3a70746f21ab63dc30c3d394cff04a702258774e6416657bad6256c262f13fc5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7a055d9f37b16e68df8ff35a293e6bd2a025d8a3a95b20b0d22b996838732dd5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:979c5dc77e53a32256779de4b12a6620371a18bd3be4309f1268c5597bf763d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2cce24a7b86d6c1d98c3d6a3dda315a0e0373bea5d96b3f5eb35ca217be0f18d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:68c24ba169db71f86030af2dd7c9d1e371d4ccc33304c0422de851273d17cfb2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d679677cc86924f33803d5ff7a5d135ea7795ccc005c9711b1c163b7b95129a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7d81573b4a22d49ecea09550b3a20d43e2fa693d28a69acfbc59e670fd939565