Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips, 4.0-alpine3.23-fips, 4.0.7-alpine3.23-fips

Index digest:

sha256:1d3e41c331f04a4f163ba76431e539149835892818e73badef8bf44bf8d6b1bf

Manifest digest:

sha256:0751c738bb4fcbd87c63419c199d4013d4d2fdbc242f48e3358f0e83e6f5a298

Size

11.76 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:dccf9ea7acfc2221c9e5f8afee89bf0de6b2dfef1981a6391718339555aaaef3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d1756940e6f54acb4fd7e8d7562932e582adaad6219fec624fd03565fd84d6bc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:861a499aae0ce440e782eab8d0c6a8b8667809445d8ea4f00a1dd2953338cef0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:fe784ab4c5d5f2109f68eed858c976607e6affee2710977ab49c38df433684a8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:70233485bfaa024daa7bf5a31e98f5ccbfd074b7979605b493111ff83cb3d884
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:42f4bc62d91c6dc4a4b755075a0be3596a0c46d7cdf80200342e130ae25fad33
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:ff98e575a85f3590b177d83f28ffd571ef1447a00e0727ee892c6eeb1d96a4a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:db6b0da163d2eea10ff63cf3484e27b227ff59817e11c2f9b7b3d903390be333
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:c34537704eab49ffb74acc41bdb71e1e4526e797c7d1cc07bec7cb55e2c543c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:81f0f4d6955e8b589b44d135ff889febbbd7a845f6a2d34b8da7cce3da1ada12
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7b02c1a90d952f5f1bbbaf78bd6f82e58f9fcade202b9205859d17a7754e4fc8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:2e572da512d7c2772ab66691bfa8e9455c6f7c4e04b8ff1742479def68c28bf8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:8c10f9778789df851e8faf1d62435815627f13e99f99a7d14c1ffbd19088f3f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:52cfa4e3a52459dd661cdf4758b46b04d8089a5b466cd93e3137699d32b7a99f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1a349a9e84221ca4e588d93718ddfeaf36825547dd5b0908603cfa8e08b0f443
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0364774b79e9e3ccfcc0587bc1f6e0c76916d8cc34731710a6dffb010b3d0078
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:beec1bafed70cd9490e900c0b2c576ec7ba14920232a4412b393b7e161d6f51a