Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:b00314575aa0a3949e92023db6bead326156defc95842279570e326e6317ba1b

Manifest digest:

sha256:d39964e5a5a1390e4e27824cc15a0f6d9fa559707bad095c2703cd8d42e7d53f

Size

23.40 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:67aae510666e2d0fc5892340234375ea65a7657988cd04ffd2c0bb1bc9660468
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:150d0d2b1ebd1aef56b6d39ee8615f2194f1611432d0b6585db6f11645e72b1c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:d3a2dc2fdb14279d049e3a8cbf33991b58de895e25de57c198fc758cdbdab7b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6c478ab7d7fa429cdfb64cdaafe6797d481870db286e09419c8225c225157603
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:5cb4b68b441a9bc5ebeb43e91d275cb046c93d9b70aefe3dd584760a08d6e97b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:96389a7771d3d51d72bed20e00b00dd3bd96c00300a9407c7dc737c9c0932303
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:6fd5da095460cbcc090417888b513045183c70b46fc441c1d2a993aafb9616cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:93e5261f7be46ee0c23b19e8f61de7b711e6e6a43c3d4b2196ed9b37e6caa5e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:312ff375c2a53fa13aef88e0bed63b9c6843bd0232b6d082c6662bfb4859ccad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:f488ca7c873f978b4a59ba0c62a630dbf8708bb7e84b9148e5ab5bc2ea590c63
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:da665bcc3a0ba027793c3fd741415d11cba81e603b7ae6b2d1419fc70c69f650
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:16dc12867f632e28aaf1b308ec5a7d2b3fd2b0cab531344fec160ce369d57c67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b045d75ae22ee3f6b590d742ea1218f4ef059c8968679b7b345b2deb7cbec431
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8604f4155ab7314f4f74b3624727a26c79a078ae15872e6cd57de2e0d56dd94f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2480549eea1cf61d11310c616b9000fcc5fdd63a654c8072582fcaac18e1632e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b905b787eb2adc47f5128795a6f9b7cf7e3a09072d7b5509dcab0f5ba5cd1e6c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:57635d582b642585063625b9a80b1e4bc477eb5f75b404ef3dc2d468691cbaed