Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:5e0b2f463af97712aeb249a74200af137666887fb3e0fb7545eb2a4b93e98664

Manifest digest:

sha256:dc48889d82ce232b07f2c88497c0bf852fe0f0f2f1cfe2da2ad813033661a873

Size

137.47 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:63d235d8c27382e24f121cd8a6f83de9e27ba56a8544c1ebe384419248acea24
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9b7a306938b54655c4cc5de8c5bc25e04d6d1bf07427712647528a48c7815790
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:fc1f83f42070c0cc0947a2b9810b535f6d8e4af907afdc41b377b2eccf65e74c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0f963ae2d414e8a9796f9e618ba90d0a64b210fce5c2f3161ec11817b7dacd38
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:b6593b15a883b726454e85f47a5ac1cf55bce5994533844742923a073764f94b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:ccfb8255a14ea83312b33bd09cd7e516528f637daa80ae2eeeaca579acb2990d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4c21b05a9b9cd88a5c30e94d898a4ffca728dd22cbe34c89c3332d434fbd5faa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:94d664a912b02f7eab2073a1cb6a9a38fe11134b6232c3dbb0338845a9ad20ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:c34eed1b1820c7182487ef0536194364b2447fc47c1a5e41e9ab26ae66275444
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1fc50a30fa72d90be6f4c62fcc94e2dc5b6cb8ef3a6f6e588e03ef8296c5fb87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:7b40e86ecc58644c86245ef352faf84d3a264a86cb3362c20baaae98fd6428c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6d2b8bcc8ba70b047307489e0e95925661f349bab5e794dc86fe638cb76f852f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ac01d35df0a53c6162db59eb3469b941444851a7ea9e730244f6e8d8ad78fd8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f349210e786e120cab61603f934a6d4e3cb3d25f3ec71d22cbc6c05a2fc8490b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ca05514c2a42e15a5ab02d41ba95d401f8eb57e5d661175ba63051dea332fe81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:9da0758f7bbb14e1c1b14b53b2dbb2bf5b9188dc1e1f22b3de7b88063b8691d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e2f2b6694574521bb332818d81117217394b16f478ddb679cf4ce1270ee991f7