dhi.io/ruby
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev
sha256:43ca8544b41bd890cc7a9a27ed3c385f00b7464265c7a5379e6255ab623e4ed3
Manifest digest:sha256:e1299b5f264ae6fbd2bfa898a09ff3ed6694db49b6f184807816d016bb84008b
Size
137.45 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ruby:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ruby@sha256:bd8c8717ee0f96a3c8f9d1d3f732420fdfbbf91fa890d0c62fd6656be9141b71 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ruby@sha256:013e58e4dee5963c131e5270522711e76386b56ccc0c4b6b63eec0b2eaafdbae |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ruby@sha256:500cc2cc7f129d0bc2d6098574a262923af3286e303437408b3845b5c0c703b9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ruby@sha256:76f2b39ede7c9ae4291d254693eebf04f09ecc0f13939bacbcf0f98a1edefc7a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ruby@sha256:4964ffb355e528ab8e59637fa8c029f80c0007460be8b95efca7e3cffcabcdfc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ruby@sha256:c8e2c8e57a1c2ca55ba67067f15f1653520d74250f90baac28a3e5723f3fe6c1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ruby@sha256:cc275912f01bf3d1305a2473d5586fa9e7d476a40b6921f36039af32dcfcc039 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ruby@sha256:283518f962bb40fa1a599dc7a83aca2942425ce0d9a87a21e145f12746497c28 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ruby@sha256:6b30a1f7a513d5be18b4ce4811c18688e2f461570c1fd9a994b93e7908644956 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ruby@sha256:ad9da2337d66e5e7c064e9d56c1bb03cab5eb0a7124bc5b22963efa79275ec66 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ruby@sha256:0ae6792442ad15cc3ee5b822ae922caea240843a48a904287b1e27d32eaa0935 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ruby@sha256:79398be8c882c5526af48e5be72a6c24347706f4a6ab8aa3bd73eacf78521526 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ruby@sha256:042e68bc188f608c8dac8a9e02c38f43cac4e5bd08eeb66f31e6b95bb2407c28 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ruby@sha256:652fb19125edf5d4b359034cbdd58b41c3c4e49895a4109ec0f3b520bcaec238 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ruby@sha256:23b5d603aa9580e63e39fec2ef08c9fca746ac933e92da76cf6044e496c40ef4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ruby@sha256:dbe9406d254eed64e9b96ac6c8cea45fc4aaf651c4b96f510d43f0ce85f9917e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ruby@sha256:32262c7085c429ad2135fd6a9a8de5ce70db31e0910df1971e7e83543ddf2e9c |