dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev
sha256:af9c6be8500cf37cfdc759a0cf38716ddc757432bd2a7e79d5df618bde27a51a
Manifest digest:sha256:f596d57809e25497b518cede80099083d6be8cbc93ec4b76e209a841fc27355f
Size
137.45 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:d00e668ec92a4c9fa15d6a527055e85301da9982d37fb0bb612e3c765c060ef4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:4bcfcf67572fdb13651e7e4a7c985470858b4a5316f48dcdc7be6b533b9071ca |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:168db89eaa0134bc095af82618231e882cae951a2aa2d8e273460fb8f1ad9142 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:25cf985138a5df84b2abc8fa68c8f8836054a5d95f9d49009c9d6cab486093d6 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:1fd8d4a19f620ba7aab9209fa8a2c16ed34c918a51adca1326bd263060cd9fa7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:db8ba2eeb850bacf3d5afa29beac59e0a1ad72942afebddfe9c6fce2890a8c4c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:03cbafa33a08aa760741ac3c33f90179e1ee2eabdc60587aceffcbf2998cfb06 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:38290a885a3d3cfd1a778ca2e3a2083445fdb6c6ea02165ea1668c6e8a12eac3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:71ea2fb9e6c2864480a1d1bed363635d434bdfa85cf5abc348018dd925ff1484 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:abc729e4d53c079f2f37946833cedd07440ac0adebfe88ae24cc06fef9969e78 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:e0909351a4d6c98a23016f97a25954a6da4c1913a92f268996de966c9eb0518f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:ff4eef4f70addbd4a438d23737c446159055aa39427d20eadb08af5a5c2a0619 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:61240ddc2e07f91022746dece74f2ee699549942b8f7f9a504bfc4be30521345 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:e2bf0d81829138e7afdd87dccd8c68e778c350b8181fe46ac094881fabcd18d7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:f7a664dbe3a3c604574ccba8ce5a8c39e7f4ec223e5cf85813cb6707bfcf1191 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:d8347c57c3fedb0804792c1697dec086999dbe47bee1186e1cd43c8bdfee598c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:50a1956ed3cce7f257b6b59080a1cf2a4d8e453f349747d3b3a051119ec6b411 |