Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.7-debian-fips-dev, 4.0.7-debian13-fips-dev, 4.0.7-fips-dev

Index digest:

sha256:8ead22473037fa6689b818ec27f4cd5d81987e6ff78cac0eea7969e287dc05ef

Manifest digest:

sha256:f4d4bca827fb616f75cbf6187698d517bc295658420b55a000a143e85dc3e463

Size

137.45 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b97c110b720dbe1a1d7e3c49a3deb264425ff4e2994f9ce1b313f48e40d34e10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:efaff5fb78107f45c4191f3fd8d8677807ae6934ca0fc7dde1d88741c6e97119
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:cdb8d850d173ba409cafad3df693412811dc690ac30b77ee0b413e27ac0e011d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8f9846896500210a7b11fbd6c1e69254562dd7ffaf066f82b253e070bc0235e1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:af41fafd5e203e8f95de7ff94682736d104e0a8ac6fbbfe15a13c4ab971a5c59
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:a66e46bd84ced78a7459ae2fc8ef02411f96555869bbdde95acbade9079c6eea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:723dd16db1e43b16386c1a40f35f0981816853752ba3c8117c6eaf5150316725
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1599157c6facdf55c9c90b63cc6f764b3ffd6bdf746c9db2fc0a71733db19ecf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a374951fa89c1674a0bc6eebfbe5a5bf7d3197e1dddccd0d2e697d3fffc8bd77
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:704220a6d9c2589ba5fe2673070c1e7ae737eb650a85cbba1bb28b794a17c02f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e2d56a81b8ce82f73701957632ef221a185300267499273b4fb09162b0945ec5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:be339a578207cd98ffc3c3e8f4a590ff3fc16435014a67c0c202d5db14ac2f24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bede1bf7c70feb6503488cdb7d1f2069c74eb7d706f2e77f1577655698186cc9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d594d1b6f57755d0d6315eeb32eaf404d3d2024803317bd9c3cc94f7d6087500
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7a4793727999a4a29ec770251b8a640c5a77b822a9ae145b3dc0de98b58c042c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b04784e7a2c9c73e75b36f665fe82e4c443fa45ba16fa02957d417c54c8d112b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:3f6c747cc8459a647c18160df3c1a2d92b2cddaa86fbc9d7216acd27d0429d97