Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:43ca8544b41bd890cc7a9a27ed3c385f00b7464265c7a5379e6255ab623e4ed3

Manifest digest:

sha256:e1299b5f264ae6fbd2bfa898a09ff3ed6694db49b6f184807816d016bb84008b

Size

137.45 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:bd8c8717ee0f96a3c8f9d1d3f732420fdfbbf91fa890d0c62fd6656be9141b71
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:013e58e4dee5963c131e5270522711e76386b56ccc0c4b6b63eec0b2eaafdbae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:500cc2cc7f129d0bc2d6098574a262923af3286e303437408b3845b5c0c703b9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:76f2b39ede7c9ae4291d254693eebf04f09ecc0f13939bacbcf0f98a1edefc7a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:4964ffb355e528ab8e59637fa8c029f80c0007460be8b95efca7e3cffcabcdfc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c8e2c8e57a1c2ca55ba67067f15f1653520d74250f90baac28a3e5723f3fe6c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:cc275912f01bf3d1305a2473d5586fa9e7d476a40b6921f36039af32dcfcc039
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:283518f962bb40fa1a599dc7a83aca2942425ce0d9a87a21e145f12746497c28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:6b30a1f7a513d5be18b4ce4811c18688e2f461570c1fd9a994b93e7908644956
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ad9da2337d66e5e7c064e9d56c1bb03cab5eb0a7124bc5b22963efa79275ec66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:0ae6792442ad15cc3ee5b822ae922caea240843a48a904287b1e27d32eaa0935
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:79398be8c882c5526af48e5be72a6c24347706f4a6ab8aa3bd73eacf78521526
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:042e68bc188f608c8dac8a9e02c38f43cac4e5bd08eeb66f31e6b95bb2407c28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:652fb19125edf5d4b359034cbdd58b41c3c4e49895a4109ec0f3b520bcaec238
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:23b5d603aa9580e63e39fec2ef08c9fca746ac933e92da76cf6044e496c40ef4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dbe9406d254eed64e9b96ac6c8cea45fc4aaf651c4b96f510d43f0ce85f9917e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:32262c7085c429ad2135fd6a9a8de5ce70db31e0910df1971e7e83543ddf2e9c