Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:66c1b92d641066817224f26b95be9dfa96d896b04b2589106a12a2fb9274fcd0

Manifest digest:

sha256:49f1d596836a37a19a3e3d81995928ef6115d2f4249098750a1b80a0854c3c20

Size

137.50 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:285e6477be653ef46775f1011ad766333d0edb76009d367caca3d7bf5468b5d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e7ebe3fb5191396fa1f555d7e5d1aa895e93641524005f30ebde6820a0450a6f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:07e6adc929e8d895b7082e9e034245509e764bf457a9d79f981ed2e386cf18f9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d2679c554e1de32e1955930e03afbb95d7e8c017b4f88530818359cbdf6f9fa8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:374e0c23a1088c6d50a224d4a7800de1b1d053417a7bb11849a0ae6c3d4572ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:daa90e02d28dc5d236f70356c7cd90d01d2371d29a6a46f25f14fade72acaa2b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:a964654fa1afe76bef644a8113e713fd969a09ca75b53bd03f3f7ff59418ad48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:92637740db9addbe7abbfbc548cfbd970d155ed398533e81480c83df8430e94d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e947dc7d62904363aba96c9df2f4da99b8cbc0b6d7beed4b5b0caad3636549c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:dbf43b0dfb4add5d12499cbfec2aec59f505b698131f92c93a9ee1df9bda1ed9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:d475843d9be6b5eb410752ac51eb85626a9b3d6cd03903c5e61120f5d514359f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:775123861da307deb2622627e2cdfbde218502017c40e0819093a79848414754
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b47e7f3d336b89da609abec50a9fa75e6b680f25119fd54c68cf0453adfa7c9d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a50ed393d41470c809a2639e79b5b475cd1d7c9a03cd8a3d01543b3ffa5fbeb5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2291b1d866f3fff59f43accb779d6301097832960e342b4ee34c69b5ec6d662d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:1327f88e3b585db0c24fc707515beb1678c00541f6bfbd0022c4a10cbcabcea5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8630013d8d3edd09389aa12fbd56fccf96ebe2fac7a2fc6957bf6a34bac32c0f