Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:e48a5d07e7eda5681cb8c1729703ddc46a20df0d30db2ab8ce14bb0ee5d763a7

Manifest digest:

sha256:65eb01a8abbd8e70dd0008db1ea940c68b0de3b782d5c1dadbeb60457e397605

Size

137.49 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:9cfe48ed68b5c38d5c47f2d78002602915d0f7315cfe1a16e3f8039efc474bbb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:2308b7647b6ed997c0b1ed351080034c449a0e45a27f9fb65b4545a120f75f90
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:9098003fb4ab6776b4b1a11d14690b5f0d1841043ec1b392ba2b1e955c51e9da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5ef16a5e77ae2e8ecdf02bcd9644eafea2133a19c180b71ada13264b35693fd5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:4fe8ccbace59f1577415c07fb10cfff2e427da54cfc635d44aaaf6c48e503918
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c181170edcbcea73e3ca865a66467a2937287a480d0c2e44c09f3dffe695e816
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:37c49ac509c2f0e565e75d8ad2f98eeaa4eb7634e070ec350f1c96fd1039e7ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:0501d358bbd6af18df01d6bb9689a6ff034201b71eef82e1e51961d700771206
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:04b65a6b727addb429820275e855165c72ef06dd163aa047e9bcb56415030eed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:988a72e1a7d0a5519ba1dd5e73bca26b7373c69c6ed1eaf844149fb98626ed21
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:75240f33903ace93c776fa522d84207464362baef422903bbacf5b3bd6d1e789
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:bed7c15e467553bd7dc023def37409e265226433cf66d93162e41d4c22502d17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4d94f2fa7e569bd9b20e3c6a7dc479d90b2c63e113d7768ee00e4e2d41ecf698
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0493110294641c2f407bb81728770b2a69c51407b11195124d09425b572a5561
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0afcbeb2ec5b36339f0180c9338b569302bfc1e605c26327dc425fc616b35f83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d69ce312aeb22600cdf53075b0c2c8a26cd94eace240551aeb467ea383b6209c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6779e886c577cff82b3ef73707b692cfaf5826e630220693433847697cd0ccd9