dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev
sha256:66c1b92d641066817224f26b95be9dfa96d896b04b2589106a12a2fb9274fcd0
Manifest digest:sha256:49f1d596836a37a19a3e3d81995928ef6115d2f4249098750a1b80a0854c3c20
Size
137.50 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:285e6477be653ef46775f1011ad766333d0edb76009d367caca3d7bf5468b5d8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:e7ebe3fb5191396fa1f555d7e5d1aa895e93641524005f30ebde6820a0450a6f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:07e6adc929e8d895b7082e9e034245509e764bf457a9d79f981ed2e386cf18f9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:d2679c554e1de32e1955930e03afbb95d7e8c017b4f88530818359cbdf6f9fa8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:374e0c23a1088c6d50a224d4a7800de1b1d053417a7bb11849a0ae6c3d4572ec |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:daa90e02d28dc5d236f70356c7cd90d01d2371d29a6a46f25f14fade72acaa2b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:a964654fa1afe76bef644a8113e713fd969a09ca75b53bd03f3f7ff59418ad48 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:92637740db9addbe7abbfbc548cfbd970d155ed398533e81480c83df8430e94d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:e947dc7d62904363aba96c9df2f4da99b8cbc0b6d7beed4b5b0caad3636549c3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:dbf43b0dfb4add5d12499cbfec2aec59f505b698131f92c93a9ee1df9bda1ed9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:d475843d9be6b5eb410752ac51eb85626a9b3d6cd03903c5e61120f5d514359f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:775123861da307deb2622627e2cdfbde218502017c40e0819093a79848414754 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:b47e7f3d336b89da609abec50a9fa75e6b680f25119fd54c68cf0453adfa7c9d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:a50ed393d41470c809a2639e79b5b475cd1d7c9a03cd8a3d01543b3ffa5fbeb5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:2291b1d866f3fff59f43accb779d6301097832960e342b4ee34c69b5ec6d662d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:1327f88e3b585db0c24fc707515beb1678c00541f6bfbd0022c4a10cbcabcea5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:8630013d8d3edd09389aa12fbd56fccf96ebe2fac7a2fc6957bf6a34bac32c0f |