Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:e7df239216ff8556af6d393e32884bc6fbe2a1dd70f8d5a891f4f8c3140c7793

Manifest digest:

sha256:eea05ab79359ead22fac26c2bce0d1c9b6c5e3791ac25f8c9d49c21b1310d0f5

Size

23.40 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1a8fad19b609119c808f2629d9f00b996b8dcfd4a358ff0d5cdef03908634c63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:643f9e456746784060d2c43b9dbf589927e04efcef96bbe3d2b50ec2d58eb75e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0b95b8a01f272a1f78858539072cacaf0f13ee915a51b7ca7808f44f2118329f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:5f40d186c5532d9d469441991fa4da38e24b47f058faa6fea58de88d7c37576a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3b9d09b32fa94e259db871de27121f05ea9be79de558befd045e1ea768541ad0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:aa663e2427b399831b339a27ef89eef7b617636146c027753a7ab2c298f923ea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d213d9fc17283954bbdc96bee276784737f4c8f7f6a4c4340a6db6e8db388f11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:589081eca623c9f37a18c4e37e598d0faec4ee3c88a3e26aee9f622ec7698065
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:90c14829bc740afa6106769205203387c17ec87b9d027c63bceafddb4ba053d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:58ed8560b80e62d11d75b063c4469bdfaf2614b4e1217468d584161f518bf30c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:d326b63e972094479c14ddcd6a9dd771b181f24bac3767a51c7ce51775ad8e32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7980a599caa8231f1696d4f831a6f4cee6bfe423224625f23a24676fa12316e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:13ef3335dc08a30b0ce4b1da8d11878f0e2ee566c6173e88f54d71bd1d4c8331
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b6691a6c1d29273725d5536221fd1b14cca2bbd3d9511c6b8c6937dd54da9997
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:9e7ad7400ab0c4bd758aeed15bb2984a415b09f9ed905f1752764244c6616622
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:bb5a06fc2e720c1a3b5b3a6b6cf4f5748e3f6dacf3b79cb0e7f4252a454af369
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:dc6e2ddb815fe8f789c0b4bf0181eac4aec6501cccfb42ba91fe18ca0bd6a38b