Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:b1230db569f6c15363b36d624adbda286e9fdbed37c51d8072856e2ad41cff87

Manifest digest:

sha256:d5a9f4daec1e7b0544df47eae4721d3849ea046707b981aa8e1e20c3006de9b4

Size

23.40 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1e8d281f10713348ddebf5c9128a627e36cb028242eb0d1cd5faa9123d75065b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:68e0fec7b67023e2eda41e2a4eca816506ab839198ce0f34382ed0fc7f62c9f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:a402bd39e34d23fba5286ec04bc0bc0433e891471116977b5ed1a3a344a66e47
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a8c2e59b9cf03698a1db928f1b2f21eb92880f2aa87479839aa7fa5d6bd91bf8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3d4f23ba3dd4007509e27f038a9e664e326b449d6ced34741d599d0a32c93459
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0b885ec6b2afcd8aa105b7bf32a330b050b55e34e62b92b8f1ee9c0141f56fc7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:bea738a8958b763cf9a50148d36f9be01ed0f4dee861dce320ab67648218707a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:95fe6719433ecb920aa47816c6f591d97c8e26870944f6e4add4551bb88119b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e7a9e89accb25eb5e42be7d11045aff5f37b90ba92763b75d5418b2a46174286
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:bbe280bd9b77cdee57bc511cd20abbdd37bfe237ab1260416ead0a241afd6b77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8e2d5f4f6e182ec167c3ff68700a8c61bb3ed5a8cf5c882c41c716e551c55b52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:ed2effbc07d8ed87109c7770ce5659140cac1e9df3e8d1841776b63d69046f40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:3a532ca0226044c173555b7ec7f5a947de3b177fbeb02343221f1910857de12d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:470840be9cf6fcef4cdc156da96e1700afc288c9b5f23dc6b88e424790dc385a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4d27b6879d8bad9627c62d238663178fffcd03eb73aaa4a3f83ace99244a052e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:17ac36f2f741e297342ee11598c95ca0ef636e551b4e481e0b314ee34fcaf888
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ebb2ecabb88fac53610c549345219eda6e1935d6e6eaa4ea4007d9731f37a5be