Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips-dev, 4.0-alpine3.23-fips-dev, 4.0.7-alpine3.23-fips-dev

Index digest:

sha256:4480a6ea5df72676b3cff7acd9383920b83d130fa9baa0248d3196dd1dc5252d

Manifest digest:

sha256:3f78f7bff5f52a82e6a91d5c5513b2ac1aff701f733f133c2f1a05b492809b4b

Size

94.51 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1d98dda69f07f31cad8468ad848178c12d0d8cc68d64f09f3ae4b5f8b04ea931
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b51e373f14b52606bdd0094cdd6fe6c58daf0a0069f9a1ddac8ec37c2af0fbb7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:294fccbf9a09d140911b820b4caa337db75cdf4a994fbf93300b6482b3fef931
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:59ab991a9aaadb0e93fc76970fe73dfbee14551a74195a5580ce2e6c4975a8f5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:47cb08132584a678aa4bb2c1791e276b1b601066eaedccd5d0c56021742c59e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:91e8f5f6df8cbfd3ae1290b394891451f852980f2734f34300575c2814a3b4f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:9c4ed489bf8a381afeac3bb793a9e7380ed23b48906f482d7bc2467784d86ada
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b404463bdff18fe5b23cf99531fd636c3707fa24a41846d6c41c3670904d949a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:90ce84077e846a7d109cb10164c1c025ce652185c42f40dbd9fe3c57a962ae73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b812d2019834ab0bf2fce266e9dcb1667a6c59994e129c560dd9d5c61e636439
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0bd6b49200807055f6af910f46f72762abaeaab300a37fb2a41530fa631237e8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:0520e6833bea58e8931b4a0a7e42a8a083358dfcb2036f83d94b08fccfa5ac03
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4d74b3c7bff3b517310097c407626a036a026a99a78bd5139eb3dd6af2a015ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a0cba485f9098303244ec142925c2c5776037ebe6c69363e85748f99328c2684
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:891d0b6c37aa3c81e4e6656def8be4d8247500a11350235738b80d876b4b57e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:59e00fab47f867a18006335249f18987b8a7edcf3fefc2c827f3a682573c07e9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5a79b20d9ad41a361c008e9f82d6db250a3667af033a3d7f3753f157e6c768ab