dhi.io/ruby
4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips
sha256:a2e8d23c063fdff709d798d9e45ee8d19af58d4684a36e90ace93c9cff6ed0fa
Manifest digest:sha256:491cf5483986342458fb3a76609120ca512b79e374daae647aba560874de36d5
Size
23.40 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:7f3d610c78fc7aabf9bfc98133290ca16720fbc469112d186cf80b28c93372d8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:f5baff15e719d74c88adb7cba4c8e468a8158b4b75897f205a4772106d900ed4 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:a6134f21ca54dcf6c380484e112eeeb129095c218abdf2e66d1cc6f2db819cec |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:0263848d3532827005a0ba223ca1ed8ad7ee3115f620f41d83e60ddd6dd8fa60 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:56f4c46673551483c3b5ddb61c4a24945bf04c474f5424bfeadb96c135fd6fe4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:5dc80df41447871ad9da3d625fb67444d79bb3836fdc70c8e98ca9d863ac3ec3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:bd14356823a304f9be7d95cb90613e50e9c28e36f466beeb415b1ae57f504c1e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:3057e6e2e55b6510b97d3c44aefba2a544f07618334108da7ffd70ec5d289906 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:80bd74148b96774bf9304995a694fd88e85e1f4721dca0e068e27710b5def6a9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:7f77a8e0e14399660fa98113ea28f23ad2e4a1af70f4618a71bac7fc2aefd846 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:539f1dde27cfc4691db5d793eee780b6914ca999aece4c5265520407c9a35ff9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:d0c43575bb336e7d72a5d3e687f8c62e491ca47b4b5b1bd670f7874585a59763 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:d095c0f26fe54f4743746c935290528d474d9b813cc461cda2d6edff7e2826b7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:484790b00d845e257ec07904ddec936ed0d411f97f1c88645f53b6b02b107e5b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:9c99c2966e51e030491bc149da6ba66228489d320c20083e236a67fab9a24a6c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:c983ee13c85f0ef83b60ead91da8255597e5dc73332929c4a5c5afd3542c27fd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:b5ca6c2dec0ce86fd3622f703b6b2779308e17253f778fdb143532afa422ef2d |