Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips, 4-alpine3.24-fips, 4.0-alpine-fips, 4.0-alpine3.24-fips, 4.0.7-alpine-fips, 4.0.7-alpine3.24-fips

Index digest:

sha256:a0f6493b3cfb88e351c81fdcdc9ccb18480e59b02b7491bcc94a9a7a243dc11b

Manifest digest:

sha256:5b88829d2b3965718b1f9c16ad9dea192bdb19110e1e1e8d17c771df2d277234

Size

11.76 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3007365ac0e2a16086848fa678c55b7e9448200d1f272e7bb60d727343ed46d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:139f47a041aa1de7e2f8107995a6ae9440cbfd24ae3edf85bdcd5591e6c59bcf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:d2424c220437c471cfb079a1b07ed4090d85e37f21e1fd3304c948b1969b1262
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2f9f7b97128cd834a256cde6454a98b7adaf5e8d7d1a421b5f26434cba5066fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:6433ffd2dd2b058ea8deb5ab802c7e725613309f427966b31a483235d11d91ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f764d1459488e2527baedb5572183ba75974d55d875d41a186348b595cfcfadb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9922908a7ef7517e569a4f3c241358e37b5498e8c76fd8911ccc010d698f9691
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b2b62cc329585542dc979a230097ab1dfc76cee3d9b6a28bab9afde212db197a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:fb88aede563d3ec0e05afc03b9fac13b029f009e6b0710829b327e02522918c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:5ab9a83273c14ef76ed0756a0accf89e65790a5ebc538d4517981e1f0d349e5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a1a252f84d802ac71f401dd4c999240785db67fa914df6703473825c59974b4f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bbde13fc79debc65d51a47e3d552132a24c99decda7a44ff577e2e6c039ea688
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c98a14808e51b4e9de1efcd4ba3a8305f7e29a76b464dcae7acebd40e382789f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ddd907f15e23ee4ae474761c00042de9e5766a2dba594355c4a8f8056c41b791
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:6992ceabe030d93638793ac7d4423ec15e12c7d4707e303de7330b62f81ec306
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:163558f11e73cc4f20ea59a4331ad02245630676abde735ed3ae8a0a82f3ff61