Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:c6ec54e562a5134bd06cdcc7eaeb6d3a1538a5b7cbaa53ccdaad950072070380

Manifest digest:

sha256:44a67ab80872b37530e720e74d4aea0790bf30e15d4761854d38832f9f8bdc08

Size

137.50 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a692227c53f5290b83443749cc88656a641b5cf9c3f4dd1c761b516613fd3d75
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ee16faf628d971f7fbf593a48502194fe87a0710152279eeb5b2fa7646f37d8b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:e0fbdf40d28ea6f1bfe98024945a59163901619c129f0c4f5b56af6af0b8e672
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d0724ffeab40f892b14abf393b1c86467db3042230ba005f1acec206294347ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:38ffc8b322de09dd367c7a87e8bac505485a71547880905e87febbe76e6f9cae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d597660fca8c6fc10c49853e1dc3698a5ed4619b8053b2cf250ac992135b404a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:7acd9d5c9482e1547a6708867133425a7ae6e808814973748d7b1d474b81e974
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8d89f97eae073191b2f5a0430393fa4330cc6e08c60564383fa71667c7a75455
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a937b37900104994a8d49acf8867d74e29791445d0a74241cca31817816a87b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:55532ac60cce4d80ead54f30f6a674d1d361538a93bcd6044b80bbfb42f8f51d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:31398ddaf8215db078c55ec1e59f8e7a5e62d353b2352f1239ff4a95bccfb75e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:bad4d81b8183b64cc4a5799cc6d01e37119bfcc49070a575068645d4ef189fab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1e1ed18db5a2161c6e28878df8b331f119ebbca911974b2f54b5c72497d3d643
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f5e02dc5751136ed8d076fbaa0dd5028b8e6043e80768df28f32646374e4209e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e277978839ee0f1564a575ee77953c721d9e45be987c37f419be85b37b014c74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b21854b301647a68643decb6fb81fac509a8a25aad3926eaa07ca7b6e9415b23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9776ca9940fa2ba2653d58d092b5b81e56a5e04c97a28eaa847d78a657dfa79c