Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:bc491e9620a194b4988de92c7baf0b5941a143528caa1aaaa5a65b825de85e66

Manifest digest:

sha256:4a73aa1777cc1e0255e480c62a5e6966580903afc135f63e4b1830aed54edb52

Size

23.40 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:66129eae80cb76dea321ef7611357ce89b4b77544d76a990a32e10cb3f4b8970
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:15e46c92e4a9197ca17d80fe65124d20f972057f3546f3a60e5f04a9ca38513f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:fa8a4d9ecefed54b6d5f4e936bf16f180a2740ecaedb2a669af0ffbcdd2d8f2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f69245465e4693055d1339b4a721367960bc00aa3a38946cabbf59b831f522e1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:a2e040bd4d24c160877e9403c411f4a1e883227bf0ec667bcd386cc708eb586e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b5256b3992fefd5aa95e03f902613026833774de490c34335d790c5438ef8915
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:07a1781862e13db851b7775a86e0973b716b5fabe7dce29cef6a5050b6c5e5ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f8d3902ead1946a8d8139c9fb04d718091271a6722c1bf96bd090b6d155d9b90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:dbcced473cd147eece33355a98aded1a187e7c2a7a173f6def8c4320beba0670
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:82002346d4abe465830223fd90cf20a6f1a688d5e95c0752918e283571ac5b89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2397e3f7966947c223d60683e13b29c56662d2ff2bd2d4b3e04c03fd7925e709
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e9ac8f99a0dc6e967ceb9e251a17fbf34b0a98f19729284e5dd0b3d966f160a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:06e1e06c97550abe2239d4e5b9d925a18f3e8bcfeac9877914a0396aebeaf19e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:bbf88a1a6a9e95744482ba14d4b3d7e6feeb466c7aa30242371e02bff9ed228e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e733c1304b3612c5b6c403412bf0f7adda22cca1e90ae53d1b3a54348141d7ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:bb03562c67624a9dd774b5584f2da30014f95dff28acfc91627c9bdfc5e31330
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8952a9835ca129442c36ed5be244c7bf61d8d99d3cc1cfb4c9e179d21dc8db16