Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:394ec498c2aa0e35e2221f7607448a11993cbdc1db6a93f9908138d9c34d9c8d

Manifest digest:

sha256:a9866940088c6dde5c17aab5f69ed1382930304cab874c786ae717d8f5ffc09b

Size

23.40 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1425d3a96a15d285d84169a9b128760cf9f3d75074d5b7f8e778d3d24c5476d3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e53d54bb46f6ddd1aa56e9481f58f0e8bca48246ceeebaa755af7903684b8526
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:762ffb0e6b3f657a50b0f2af97a45d287242290fd46e4949e7f6ae7deb820e94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:93531d4b3c20f57d53232a160e6f10d987f1a9017e69b9942dcec5a83a10b425
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:1524eb0b5305b0bfe8592052c74428bd813577a2b527816bf8d9335838558db7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:7ffab252cbb0e907513f34dd6026bd4926d3042994daac9e01e4c936aa747dcb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4e2f5e9a80dd5d58e57e9e6a95c403e54933ca9396fd18a1955b7bdcba0e9862
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:41d8804727f11985a23216a0fb88190ae276ea4dddf9093ee12ba30c8435a3e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1b850a692409b8a7f38aeb659db9eb4ebf60270f7265e43543568fde20def196
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:af98db9d34db8792034b8b2acf021736a7d2045ec61f4822e3ad08e10adb704f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ee7063c6d262bbcbceb1d0a3b0f4f57fc23af0d2a1857ac54e379e4040802e8f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:83573b6ef708eb50770a259010f8c0afec5fc77f2200bb08d11b6c5c51c22456
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e54824932aee9a6b9ad6a39a57f57b1fa0681abb1cd278bae3047251cd5551f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:726bff6a52d55d4966438d0350f408e4542b219fa2db94387dd903fdb112082e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2210e3e5f2e40ccb410f6cb264644734336ad5426291ada2b61efc27f058b734
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:38a66198f19a4cc349f0840b180d16215b1ef6dd8b14aa7fee4daa1e8a6a132b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4b62ff38b95d3ce6c914739cafb572ca1aea92cc71595034e30f6e76f92cb81a