Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips-dev, 4-alpine3.24-fips-dev, 4.0-alpine-fips-dev, 4.0-alpine3.24-fips-dev, 4.0.6-alpine-fips-dev, 4.0.6-alpine3.24-fips-dev

Index digest:

sha256:43bd60dbd720d30fd16ce280e8d854ce634397b8f1e12b04a5ff228ea0c45f34

Manifest digest:

sha256:e1892dd61166aed452b775aadee1655b4c4f2c769aee7cddf11a42e9c4b71914

Size

94.52 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:b6f73c034681cb95b676dc76d599b23a069d689fabdc1d875e8e1e8b58d6b980
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9881241346c71b91002a5a8fe29ed0b13006de98cd91e3f21323e06de62a7bf0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:77f9d7652ef4c291f801b324f041fb8384313f4f64e4b1e94ab669c8cd907334
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:bb5bc0462a0fd85cff20b2d5283e2b9a946fd9b1d63453ee1b2310702c0ede73
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:7b75c65bb7de4403a297452f71914161b29920b6f06baeeac13eadc0bea2ba44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8337b0f909704482910923c1e1b3f8fb7bbefc4faefb637a230b6584a1a1b669
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:93998dc2974a91990f951dde320c88b5e5efaaa053ae531dd62239a474f2e383
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e774baacc4a76d41449b0d1a3dca277e20149f0fee82d897fbad0c5a4f5173ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5cd518c2bf7442a6415e2429c63ffb957d74f9e4e227f6924e1303729b657d11
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:cf4bdc9d37602241dc7349bc224ac844fe81284fba8ba93abea668f441e3bea6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:eb370ec40859394143f5423652443fbff8029cf35497dc8375d7f54f42a46794
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e6c9d2816949b29a132b9dd8375a4c11024dae1434b537b9ac9d3b139c8fe1ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6e3989d0dd7f2a02c525ed92689b81f1954257d49f6dc12575464b6e8c42a544
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:652ca96b89de1ff0914526701ae2126d254259bf6f29ba29a228368324d2856b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0f37344df6e1f1135e60385cda14e6d8cc0e06f3bba8fc702b69a64f3c587220
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4482d7a5c339d1fa40e3d1cdfcadb6992fee96142c7366c0aaa8d2d2d81343e7