dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev
sha256:1935dfd0168a1d00efa3cecb4d9ea2d5592648674b519833dd9761f1ddbc998a
Manifest digest:sha256:b053cc4b56c9fcb5d2cbea59adbbb6bd3fe39aa50af19a38dfb115fdd4b3851c
Size
137.44 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:bc0eb1b1d66000583768ddff84e768f3c1e746bd262881785b06fab772f4bf7e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:abdc05bda8b25dc59e1e3d261c2e8f98ec1294dfcc8951822554afeb8271381d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:f3017f06eb89a57a7d20382fb682bf1304c6dac1a684f0d7c994688cdcf8c88b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:2d42baef7a633b80ff8d08411336f23bbf023ebde57c61f5610edd0d76560f27 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:42adb7f895dc45b392d03279cfa83595f028aeda9832acb88f68e37bb3db699c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:9000dfbab7708d1df7e73fb8f9ab92e16fc5c7a04d8cf9d093d8bcb9b882fdca |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:bce6a5558b593cb086712c754eac3d592e754d9dc22a06c41a3efa008ff0da5a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:aaed678055f084c681b19b398820a63700a83b069b3c672858ed5775cd5afd76 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:1f47b7561162deb1733d559c1e0e962df1cf2cc219412fe359d4bc05a10e60a3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:fb3582cac87f3942ddd0d0b45670ee5ede09a7b21cef1f9fc1fdfed36422f812 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:e104d33358575b2fcc1e24ce68b38416f8682b58a5f5a5a6d717f11c51e58a7c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:1b72ea55dc94145d60b8dfdd1e336fb3405f27d1f87d8ff2ffea20a70ec4bb84 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:f9900260d57595695eeeeeb297a28f0ed8371c089dda02f285d53410ebc9c46f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:5a1d0af8f8f818b56a0f94e95108febaf614d94a0351996ec0c7a791777e49a7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:d757c3b30361022eb95ec857babdd2e356849fc54de691b775c9d5ef7ec432cd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:093579bd71cd08c696867e1f7d46cec85498a8c967b5f1d6299f9d5f94b72818 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:99849a19f28e34e8ac13a4431574cf217150f80429afd184ec6da2f436207af0 |