Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:7ec5e051ed0267e7a4e9ee8b4c5523c27aa929e7ff899c8c2d81d143eef8c9d1

Manifest digest:

sha256:552ab93eaed69b51ba2347c57d8b6ce879bdecf8043812af48f31e27aac004ef

Size

137.45 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:79bfadc2b4b25e1c562635eea02c3697b5ce876ac4202d6d73674062d0387542
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:da1c4a70cd85a7bd9407e4a9835e29b46b12bced95c7262c567656f3864a2f01
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ce015f2e8ab5cd15105923d7672ab065c2f34f16757db5983606d95c66f8f0a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b925553dadcee170906f8b48ead2936690888b50c10bcb85045e1e4866007e95
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:f5d55205b8ec57a5a8eead4371c4d9db823cc2e5121fe70e6c476294e0ce5879
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f468561ef0f22caaa65997a190f1dfae304c032b0ae9e82a6c950ea887a22523
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:829108d525389dd66dcda0cc1227be17550dc3492860e1589ae4e3e0e5298fde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:eecdb73254aba6940698fecf242d03c4deea8bd0f8d52b1f36c49ef9e15a69df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7e17e2339f1eae971a03c4ac7a4e53498215d467fde7275f63b59116e873b332
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7da952e0cae46d4b2cf9294b441d6f740287a864ec17d256bb6d8d5d0c4c437c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:161f27234489a671c1f61de015fefa9cdf2afb94fa2ef6ddaf6b0ddf62893aec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:122de5b59379ce4b95d307ef8c8ed3fd97d943cb7bbaabaed03160ef5ea60294
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:55344cb4e2893f2fc7d19ba97e04f0905415026ca90d4c9d7e445cbe75f2f037
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2be6d2f4be11e34572f9166d050641493236a7dce054203f74b77163b5e9a126
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1e5f94aaee3337ef6006d56662e4732f773085c75fc35b2af5d1d68eff38391a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d5919cfd32fa6920d4bba126c76efd913ffdcb37a913da8f13e7ec5bf27856ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:a98a82b4fb6b6d92b69f7132a072a3b701af4434dad2b0dbafa5022bd8898b94