Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.6-debian-fips, 4.0.6-debian13-fips, 4.0.6-fips

Index digest:

sha256:cf9b934050b27f9d345237cd88f40e12c0b4087adaa89afb9210fb0ec20112c6

Manifest digest:

sha256:16eb3c3e643390294db43f39eacb212461a7012e7e21a24655d41380f14d0e9e

Size

56.07 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:349d981dc720c0a1208128572b4a1f0601803582662935899eed54650f4dd66c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:00080a426bcf507fd76344e86cc39c7e27b0f070ac3b12a401eec61d90939076
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:adf472f3ee44d07520dd2781aefc2dd1ba560a2171a37318d7f8ac6179499fd7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:27481cbb705a0984e6bb5bcdd180b4d7a2e6a60c494f4ba9dcacf7823da81b14
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:2f436f01bb779fc38166a44a43b55bfe81975f51c877626cf80787d05ff73404
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0f8bd5b2d96d4bdf4a2467cfa850b19ad2f63452ef4fbb8338ca59c7fb1d3b41
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:76a3ae485cf47d27ba485db99a0d6ba924472e4241c077c2f4c5a8e027ce4bd9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:76048ed32c6510647620f9f2a3f9ec5d9c5685124676b32620c926c1155b7c9d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4141ad39b8b2fbdaa9cc81046414a61aef69b4189eeb4cd057186cb9c8407d78
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2e97acaa87eb1b1e6da203ce415007b32e95845b621f08b1f6776637fbec48a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:484ff8442bd8d78fe50594e4721b084c23c731a427ed356881a8ee31fa4bd09c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:05790dbc2ae69596212993ac5a163053ba46eb48080463b810ce13580d00b283
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e815c548ae2da90a86247cd7dd1719fb64c9b0dd4cd9d215512ea6c86122ae16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a033d96c1bcd4ef31911c7123b9dd9be726d04a0bb402df0c0af85137dad4b2e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c2664dd274be985d45e77656ed8b6188dab9331e971b561de013eb8cb27c9e21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ab218412fe3b2f9bf3afe8d6dae2b32163f790c3b5be9f3dead22c1486bf65b2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2c26ff6b84280c72b48ddd76529408e0080c1e46b84950bdffa28226345304f2