Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:661b816b4169adcc286c603772a7573d7002835af1df074f4d0f64175b39efab

Manifest digest:

sha256:b33c23f7cdd742edd9f3d1b696fc901c58680c61f14468d6df47b5d2d392bb77

Size

23.41 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:478bf7a7460a8ebc851e553e404bbcf1ccb91a8649bb3e5c8acafc67d945cb70
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a49a20c117eb976522d939a0deb68102272e9beaa1c630dcf0475c00cc520da6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:c9d22de9d1a5148e66424e8ee5b9c5b6884aab006271a4a9bc3a1892abe1e4cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:207dcc4e15dacc7480349b3e56ff7a26bbdd1445a989b74ad08b95e9cd987aaa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:882b353c8a9af7fbd4ef29cb465a1c7140f76112c0ded36a1cc7cae32e161e0c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b3c0a1d3880b62bcd6f43871d9c2ede208841b8922039d2dc2c01ffd5923e2c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:3286737210bb933055a311b735de078e772372b67a55cdaa1d72ebff1ab0765a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9ee88343fd30937d7f859f512a83fefd26f330bda8b6b2d9a45b0749c433a45d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e2673e73582211c684e71d791409b69037950e94d92bf19ac63f9e868173eed7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b176a0dc130dba6c26eb83ff63e88381e7a222277adff9f25b3d6e926f2cde59
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2e2c62fad28c2a9e6a748ca7be216d5840b772f9aae2962e731c5f3ee4209ca6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e51e02941996f1669e86f340f97c7ae912934452e7ef738ce42e9640afd283a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:2417e07995caf2daf2b069ae2749b0490d228691d22887b67d0d1e07557cb428
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:2418e1ae59c6df8c18eae8464fe8b4ea1dd69b6e9b43d62c308cdd883444d171
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ac09329b2ba2c37ed91da0d0e5c86ef9e19da5584f27dd6e8c316b4aa6f1c939
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e9b94693ab7be0407888ca2cdb91d4e9eb578088f207286205f8ba576de56ba8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:049ea5fb3128a4ac1c2cf168c069713fe5225f06f24ecd55cbfb1eeefa402318