Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips-dev, 4-alpine3.24-fips-dev, 4.0-alpine-fips-dev, 4.0-alpine3.24-fips-dev, 4.0.7-alpine-fips-dev, 4.0.7-alpine3.24-fips-dev

Index digest:

sha256:329fd4c3d2e1138d8f33a3eb285e4494e138cc317c55090c4b46617066fcedb9

Manifest digest:

sha256:3cf98b98ce27561ba91176bbaaed019aa7c3ff4ebd8e4463a3a8472dafe2cb89

Size

94.57 MB

Last pushed

4 days ago

Vulnerabilities

0
0
1
2
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b5d26b2f2895aca9612ddac0d677e25704aa01242444d4f5fb4621b85658a2a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:aec11e1e21b56406c1f3ccae827b55fa9b1ceeb044769d08334e82c6c62ca434
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:be23efd29c336d0d6f69355e6b25ee27b4ec4c7a3e0ecb60c6c7831a48509210
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d5831a64686a390b68d0662e3ecf6b9b7f53b6c5ffe184dfc5bd914a53afadfb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:50face879573646b32484fb52e5153d7c2af11a8563d544ec4907cc8906c4aee
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:53db3c5417b3ec72b74de70769dda940df1a22ed0116d447495d0de0786f4601
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f5328098e16c79530c41acb3b6ddc371379be931edfe6ba55c0aa0e705b38ec2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:eb6bb17e0be1db09466696943766d510eca8eae5624c1575e491e6f4056a3c16
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b541e2aae01c9d3e9fe3a5f54595c24a634407a0cdc7151a14fd8eef290a9059
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0fc4508c0d78a34250a88318a08df5314d82e7c1bfb7e2899eb83b74a4dd2330
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5530952da7bd2e83e47f7c7433bc193e63edaee8a1c55040ef68f5d8f838dcb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:328253e297f3664fac8b4f6ef97cab4e357fc8f5c1a9ccda2fa8b0d66c78c5a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:bfeea7d133c4c197142cc6f7f414721f07cc8882e6d42f931f746c135e7ef1a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1b09c76adb36524573c802113e46f3061512f9e9e6c38130784547e90211c935
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:3ac1bc6124054b3367d62077e920fe7d355aaa332c9c8bcd47e2114da26f159a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:11d7c7ce25520bf566ce9abab2ed605cc7c680cedd9eebe8f98dee7978dbd3ea