Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:439c71c8b5f7d48d9a732e8dbd5dd68a140c580f0b9e52b993153d92db27084c

Manifest digest:

sha256:2dc2d2c298af3ad26c4a9f716928b713ea5b139d97f2e1f25cb969bd36e3c467

Size

23.40 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:32d8b8e33c8648816742520fb771d072fd7d9bc54601a3bd68afd51705b28c8d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:059788ed61526686893741c56ea152a22d5218a64b35b28ccd4942f7ee6cb3ee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:320047409801704e7fbb67e4e53f7d675bcbaf745c845626cd5083e8ebd2cceb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:df5ba9dd614ec0cf6fec5b200b8acb916de9ffbc64eef17cad330b99dbc34fa3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:e05ca9d226ba6378e328a20c4455b92bd0ed19e7f5972c71014944bdd8f9a5e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b2b1d8b556432e47034c667745e3a96b9ac69066f0500e90dac2e5ae9f7b234e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c099f8a0cb0158d58fcc6891b32a1eb1a9a4bd358fe3816942645588d09525f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:656466b7b410a314bb4e0390224c5c859332bf74ee8aedc6b4e0324ce52be157
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:924a65e28d2af98758880c0bbd96d66fb7aa6bf3f15296786c70604dc47fdac2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:56b88f056c5472a0080aa3c2b457724243b1aeb2cec3fed0bfd5dbc71fbb167a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:19a14398f5744adfd8a3f4cda4d087dccfe2e74ba7d931410fc18058770afc32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c1153f4c064e46cb30a5beb773f35d7b93e455f78f2ab14c985608a3fb5f81b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1e3e841fa18c78d7227fec3ff079f674fd1f4e5d1aeb5b89201505f0968b9188
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:4fd3327ebbe8807ce26bf42e91c1f54fd6729c74b04cb69498cf3516ea53b4e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:85399977617fa1ea37bcb7a32ebd59f86d07d98a90edbf9c4a8b8b6e49ba30b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:1f447faca37e9f4fc6788528df575a68212ba5ffcdfbd1f78d3d5687e4ad136c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:f5e4c1b33392a75278056e7bbf5a48d330a68c8c96f4222d9fdd32aed3396c67