dhi.io/ruby
4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.6-debian-fips, 4.0.6-debian13-fips, 4.0.6-fips
sha256:16dac0dbcacb7b98a45a16a28995c3a59bdd11bb6f005e29f76ca1879ad99c74
Manifest digest:sha256:b8e6e051a2d11253857ad9eb1bc20c79b586ef434fa285f2d6e9130c878781e8
Size
23.39 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:0cf4c9c5d3ac2a96e6e23447654868b079fb8a8fdabf3973188580ab29d459e5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:3c9b7921c046b14d114926fa92101a45102b9fb500ef8f8d9880ed083764ed45 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:86813fc6779c5dbd4ec0489307e1354dfa9ea4104cbd0cca3ca6e1582b0ae1fc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:9c14a9deca041023e13d9c0d507b6baacab4b87179533f693d651a6ce21553d2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:8a0252b9ffa697536dc4a4ac4f1e66a3e266bbcf00bafa67de46438e4e3e7d98 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:d264b793dedf8fbdbd5170eda84e361bfa7e6ef811bea1bf435bf87940b7caf2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:95adad28e8a0760109977bd732d988c812e2d5f5c2b86c96b4680b04232a369a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:9953fa5b805c39e30d7be7bef9d3e5bf81d787578d7c6b3abc5fde16f526ad48 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:401ed3beed8ebda802cdc486a34c64156ea6b892a6c867c217f502ef4608dde6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:7217cc314581af8403912b913420ff42eb725a84509e4a052d760cd5a2973e57 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:6074a30fff6dcaf76f3c454eca8686367cd7cf59c947716674353336a33d6905 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:cd4a03828777347e77fe36d8ec07671eff15176e9a053d64f3ab08c96f3317bb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:65a71ef5769042ebcdd127be7c5b3eae3b2b0c114ab77e206fdf3d62a00b26c1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:c6c26b8547002b3c1a5f72e92081bf19514f4ee207472294a59c3869a0e1569f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:e22730deac24762b7be0125792560f5f08cab2950e168f2f85aa5ddb4e889e6b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:41e55b14d8e5398697f3bd5408222038ed4878ce58ae3ae9752bb8157534ccf0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:9dde61df21c0be591d3f1676ae282f6448cd5b789fcd431f5b2cae74b1ad2f35 |