Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips, 4-alpine3.24-fips, 4.0-alpine-fips, 4.0-alpine3.24-fips, 4.0.6-alpine-fips, 4.0.6-alpine3.24-fips

Index digest:

sha256:e3af0a18a6a74b2479c76d317502b89dfadd75c0ebc9918936a0a891a0318c85

Manifest digest:

sha256:f515fa3c2bd422da34e61c25d22452c196dd772bda9c2fef154e88c3fca98571

Size

11.75 MB

Last pushed

10 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:1f6bab95a86e6c084b48e54d226d88e8be616e291cc703cc6ec70e5baded7e92
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:eded78ebe0a843500225e3c264271574063683c566a12c4e5546c7a6f250fcc3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:37a100d8b0f0b3ec3b9f56506192eee14361c70231fc2ba326fa7e4cd0c942ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:0efd3138c481da9fa5dcf94b15ca1fa16641004558d0ba05969c23073fdd9c5d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:31d1f5a16363a6a3f08cf565321ad52828bf6b1db8c066cb615110725a15fc70
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b4f24f1bbcb94eceb26cf6695f26167807ca03aa8235914eff1a7fe065164168
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c15ff15753e0dcfb527cdd0fd0a3dcb57141fbfc4d4b55b3d01b5699d4ba9656
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ced87b624e563a4108c51aa3d06a2d3f2cf9570c255c3e1765c74b6857d8dfc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:08ddeb2b15ed103389206fd111cbdc9135b5af60d4d495dabc8b2d22ba10ecc4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:597f405672d705906043b74ec53bf8971196cfc61746c54a1c6d66c0df9d77d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:f9466ce7ec84876919356460f63505dd2adb6dec65510081792e8fa61dc6079e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:258b747f1bfdc3bf2d2cfb91506c8f4171ac977bd8a3cf68d94dea078d9b81c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7e71da04f09402a01eb3f416a6390ce511d72a529ae95da0bd3868e65a3ade91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:339e44a78fbf0465fd25a2e5acc9ebed46a5c18994c92c1282a88b12862ec557
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ac1f260d1ff2208d95988139369f7f945b80cd8e8f5aab29d06ff09412b561e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8053688130a66cf7240194f365b5e232ebc7fbff4307ae6217f5df226947f167