Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev

Index digest:

sha256:af9c6be8500cf37cfdc759a0cf38716ddc757432bd2a7e79d5df618bde27a51a

Manifest digest:

sha256:f596d57809e25497b518cede80099083d6be8cbc93ec4b76e209a841fc27355f

Size

137.45 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d00e668ec92a4c9fa15d6a527055e85301da9982d37fb0bb612e3c765c060ef4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4bcfcf67572fdb13651e7e4a7c985470858b4a5316f48dcdc7be6b533b9071ca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:168db89eaa0134bc095af82618231e882cae951a2aa2d8e273460fb8f1ad9142
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:25cf985138a5df84b2abc8fa68c8f8836054a5d95f9d49009c9d6cab486093d6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:1fd8d4a19f620ba7aab9209fa8a2c16ed34c918a51adca1326bd263060cd9fa7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:db8ba2eeb850bacf3d5afa29beac59e0a1ad72942afebddfe9c6fce2890a8c4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:03cbafa33a08aa760741ac3c33f90179e1ee2eabdc60587aceffcbf2998cfb06
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:38290a885a3d3cfd1a778ca2e3a2083445fdb6c6ea02165ea1668c6e8a12eac3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:71ea2fb9e6c2864480a1d1bed363635d434bdfa85cf5abc348018dd925ff1484
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:abc729e4d53c079f2f37946833cedd07440ac0adebfe88ae24cc06fef9969e78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e0909351a4d6c98a23016f97a25954a6da4c1913a92f268996de966c9eb0518f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ff4eef4f70addbd4a438d23737c446159055aa39427d20eadb08af5a5c2a0619
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:61240ddc2e07f91022746dece74f2ee699549942b8f7f9a504bfc4be30521345
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e2bf0d81829138e7afdd87dccd8c68e778c350b8181fe46ac094881fabcd18d7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f7a664dbe3a3c604574ccba8ce5a8c39e7f4ec223e5cf85813cb6707bfcf1191
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d8347c57c3fedb0804792c1697dec086999dbe47bee1186e1cd43c8bdfee598c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:50a1956ed3cce7f257b6b59080a1cf2a4d8e453f349747d3b3a051119ec6b411