Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:be33d4e59df980dd747e3a29b05aeecae305aaf338d1d05388ef65b94248e309

Manifest digest:

sha256:2c5bc870dfd3248b656622648d6d82258509ab1f7102cbd0494db4c1f9c50eeb

Size

23.40 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7a13266d8db7d78ce0c272a0ea5fb16981dcdea9221832e7f5658c3a9c33948e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5349e7c28907b6a23f499f0b4f2cedc7e4c26d8a9c47e9bc6549050e6123cd7e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6428da6315d912beba3ec3b9a4352d6e59c1da3be8ca8437c6c01338c8d98cdc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a87213489481eaea9ba7eaba63fbea97caefbdf1e7adb40291dd7ca13ac7c990
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:e3df6f6ecda6beccc6772558fa18bcafe0395176048c37eab1559a450d7350a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e2ad30cae50bc243a68df00532a2c64022f22c057b4aa08ddb4e86f9a18e75c3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e910e41006f405b3429c12a531ffcdeb2e6427b5ce071df12cb33a9793aecdff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:90dd002fde8546f72cc896c1300ab056d78c9b45ad701d02f31b87ca9a52a594
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:56bf5eae80308c2757fe9d7908752fd8f21256387f2fa866a6273cc827d9dcae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:86392c21ee93adf379a8ff9a0812edb2200f5f2494ec3d1dcf59260bef9d435f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1ef0d56960e83aa9f83fc66913e6f45868e9c2ba8952d83434fc6d2e3e33de76
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e81dd181b132629dfcf482801bb278b1a4f140662999f096d69b06c11791e05b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:446cd188002a50f3a36a951237e6662cfef86ad505a31224dda385e740603ce8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b892fa51c701d819a486b2d7ca17b6ff58e7a718d62669053c02cc0bc1f35d8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7abd58b9c373a96411a5473649989fa7d92eb6979d53e5aa9185ad81afc46a0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:59f1d09fafe1f6e0dc4087a607dcb2ed2883e6ba0e8fd08f99eabbb29bcd7ec6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:1e861811f47971f40a5e0e66de588ac6c854174e17e409255e6e46f3ef064eda