dhi.io/ruby
4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips
sha256:bc491e9620a194b4988de92c7baf0b5941a143528caa1aaaa5a65b825de85e66
Manifest digest:sha256:4a73aa1777cc1e0255e480c62a5e6966580903afc135f63e4b1830aed54edb52
Size
23.40 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:66129eae80cb76dea321ef7611357ce89b4b77544d76a990a32e10cb3f4b8970 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:15e46c92e4a9197ca17d80fe65124d20f972057f3546f3a60e5f04a9ca38513f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:fa8a4d9ecefed54b6d5f4e936bf16f180a2740ecaedb2a669af0ffbcdd2d8f2d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:f69245465e4693055d1339b4a721367960bc00aa3a38946cabbf59b831f522e1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:a2e040bd4d24c160877e9403c411f4a1e883227bf0ec667bcd386cc708eb586e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:b5256b3992fefd5aa95e03f902613026833774de490c34335d790c5438ef8915 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:07a1781862e13db851b7775a86e0973b716b5fabe7dce29cef6a5050b6c5e5ac |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:f8d3902ead1946a8d8139c9fb04d718091271a6722c1bf96bd090b6d155d9b90 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:dbcced473cd147eece33355a98aded1a187e7c2a7a173f6def8c4320beba0670 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:82002346d4abe465830223fd90cf20a6f1a688d5e95c0752918e283571ac5b89 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:2397e3f7966947c223d60683e13b29c56662d2ff2bd2d4b3e04c03fd7925e709 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:e9ac8f99a0dc6e967ceb9e251a17fbf34b0a98f19729284e5dd0b3d966f160a5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:06e1e06c97550abe2239d4e5b9d925a18f3e8bcfeac9877914a0396aebeaf19e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:bbf88a1a6a9e95744482ba14d4b3d7e6feeb466c7aa30242371e02bff9ed228e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:e733c1304b3612c5b6c403412bf0f7adda22cca1e90ae53d1b3a54348141d7ff |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:bb03562c67624a9dd774b5584f2da30014f95dff28acfc91627c9bdfc5e31330 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:8952a9835ca129442c36ed5be244c7bf61d8d99d3cc1cfb4c9e179d21dc8db16 |