dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev
sha256:5e0b2f463af97712aeb249a74200af137666887fb3e0fb7545eb2a4b93e98664
Manifest digest:sha256:dc48889d82ce232b07f2c88497c0bf852fe0f0f2f1cfe2da2ad813033661a873
Size
137.47 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:63d235d8c27382e24f121cd8a6f83de9e27ba56a8544c1ebe384419248acea24 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:9b7a306938b54655c4cc5de8c5bc25e04d6d1bf07427712647528a48c7815790 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:fc1f83f42070c0cc0947a2b9810b535f6d8e4af907afdc41b377b2eccf65e74c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:0f963ae2d414e8a9796f9e618ba90d0a64b210fce5c2f3161ec11817b7dacd38 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:b6593b15a883b726454e85f47a5ac1cf55bce5994533844742923a073764f94b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:ccfb8255a14ea83312b33bd09cd7e516528f637daa80ae2eeeaca579acb2990d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:4c21b05a9b9cd88a5c30e94d898a4ffca728dd22cbe34c89c3332d434fbd5faa |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:94d664a912b02f7eab2073a1cb6a9a38fe11134b6232c3dbb0338845a9ad20ed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:c34eed1b1820c7182487ef0536194364b2447fc47c1a5e41e9ab26ae66275444 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:1fc50a30fa72d90be6f4c62fcc94e2dc5b6cb8ef3a6f6e588e03ef8296c5fb87 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:7b40e86ecc58644c86245ef352faf84d3a264a86cb3362c20baaae98fd6428c9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:6d2b8bcc8ba70b047307489e0e95925661f349bab5e794dc86fe638cb76f852f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:ac01d35df0a53c6162db59eb3469b941444851a7ea9e730244f6e8d8ad78fd8f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:f349210e786e120cab61603f934a6d4e3cb3d25f3ec71d22cbc6c05a2fc8490b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:ca05514c2a42e15a5ab02d41ba95d401f8eb57e5d661175ba63051dea332fe81 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:9da0758f7bbb14e1c1b14b53b2dbb2bf5b9188dc1e1f22b3de7b88063b8691d6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:e2f2b6694574521bb332818d81117217394b16f478ddb679cf4ce1270ee991f7 |