Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips-dev, 4.0-alpine3.23-fips-dev, 4.0.6-alpine3.23-fips-dev

Index digest:

sha256:08d375e938cf5474fcafc1db1c9fd69acc255fd44ba3042d3fc103de55d0ef92

Manifest digest:

sha256:8dc84c67dd94022d6a25ef3543259d628a495932170404c094672de47a495c32

Size

94.50 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2a10565b2955210258f9eca246ca7d2b509b5b7bae1d24abb1c6fac0dfa0bd79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:5d14e61a300d3a67974c6c0f3d7d57d8790ca18d69fbd22a992cd211f25bfa14
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ba67c1b8220075942b6521a15f629320271f46b816ff0fefd59ac744d34e704b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6ba12a7b075e75e94ba710d0a7eda05f7d851c95d40948ea87e3aa9a69cdd815
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:58e5d612e71bfd07206fd1c49499d381bc9843bcdc1d9238cd048336629a3d84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b219c3b659f707262934ff4f30bdec610b4b88362c084cfd701ddf90334c4d0c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5a7150e79ad35e2f2128d955dbfefdb8f22218aa2b8b2ef24d9e8a7fd959f95b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:6afb9732d7063992e515d336e3ff9885621247427bd0e1c1c87f40ab9a3834af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a37dba941c893c6d42f83afa143fae969d38377d8424f907e867e6f4736fa5ac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:97014abe54f1493d26dff58a8ea3dc6e43b3d9769171c56d46380351272a00bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:979bde005a5d943ab9085b0095c998bcba4237e93e275f6f12b95ab914966f95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9aa8d19f297376ce94a1392d36e7d5488f2b35468afbb5e38a67e5d9fd4dc1a9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:9e566d73beb0af573c3ccb47b69aae559efe82fc527d0e5b6c056d4507e94745
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7f4422336484d7ecd0743ce2daceaf22e727e051005c28ea6af45dd480a88f80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7258c5c17589e745162acbf84de9000ac52dda5d2222ff418aa301a396d2a1eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:fa056b87932b4b45b715227e8a956adf8b24d9104628aedd2a5753687c469104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:3e10d07f43f7de8843eb7340a3901b9ff309a1963191bd82ad3b09dfb62fd022