Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.7-debian-fips, 4.0.7-debian13-fips, 4.0.7-fips

Index digest:

sha256:a2e8d23c063fdff709d798d9e45ee8d19af58d4684a36e90ace93c9cff6ed0fa

Manifest digest:

sha256:491cf5483986342458fb3a76609120ca512b79e374daae647aba560874de36d5

Size

23.40 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7f3d610c78fc7aabf9bfc98133290ca16720fbc469112d186cf80b28c93372d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f5baff15e719d74c88adb7cba4c8e468a8158b4b75897f205a4772106d900ed4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:a6134f21ca54dcf6c380484e112eeeb129095c218abdf2e66d1cc6f2db819cec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0263848d3532827005a0ba223ca1ed8ad7ee3115f620f41d83e60ddd6dd8fa60
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:56f4c46673551483c3b5ddb61c4a24945bf04c474f5424bfeadb96c135fd6fe4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d0507cd21b4aa8b49d4e391ccf2637c7d0d6240bde91bf58b39536bfb4623418
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:0925016008b9490563c5e9a3efd11d8e93282631ecb27132f069188724136011
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3057e6e2e55b6510b97d3c44aefba2a544f07618334108da7ffd70ec5d289906
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:80bd74148b96774bf9304995a694fd88e85e1f4721dca0e068e27710b5def6a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7f77a8e0e14399660fa98113ea28f23ad2e4a1af70f4618a71bac7fc2aefd846
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:539f1dde27cfc4691db5d793eee780b6914ca999aece4c5265520407c9a35ff9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d0c43575bb336e7d72a5d3e687f8c62e491ca47b4b5b1bd670f7874585a59763
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:47a3693fe9c70d022afa92ad33e69487081b9d0d3ebc006b66f4c48f1f07eef2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:484790b00d845e257ec07904ddec936ed0d411f97f1c88645f53b6b02b107e5b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:9c99c2966e51e030491bc149da6ba66228489d320c20083e236a67fab9a24a6c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c983ee13c85f0ef83b60ead91da8255597e5dc73332929c4a5c5afd3542c27fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b5ca6c2dec0ce86fd3622f703b6b2779308e17253f778fdb143532afa422ef2d