Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips-dev, 4.0-alpine3.23-fips-dev, 4.0.6-alpine3.23-fips-dev

Index digest:

sha256:af20602bc041ac2c2e07edfc7e604244d3d47a1ee79516ffec025b4702881e66

Manifest digest:

sha256:7a5b31b24c75553e4a906959ecc66d7d43e997f760f77c7d883e486c8de9de84

Size

94.52 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:72ddfbf6e3bceac79b9decc1290fb7c77300cf6493c5e98cc3b4ba8de260bf9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1d6f01ac386d227ec97c71901936bb2a7864fdeb57db06d0381e2b1f72c803ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0588093b079a69b134d8dec106e6e23f3ab696eaec88d12b1b4fc218e3a0e36c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3cdea195a919d5dea56b3ba845bc0c3c9f52069e140596a3cb2a5bd072f91e41
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:ceacc3c7ffd7b8d43fb4b73cc226f19f3a5415d47d3c619355d675d96f14b8c5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:45ee9cf73fb7921804b35bdeacd5743f44278a72c65e399cd24d62dd520bcbc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:e9aca79b58650106cae367d394c811381c77faef152ca9a1c479235de0384a2b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9d210f31d322f12b9c875797aaecdfff52d051631b374d733b8ccbd7cbbbedd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:2487350fe9b60c5d253300234fa31f44c84c0cb7e196df620fde914639311a1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d1008454791ccdb32b14407998bfdd7b3f941e4f1ce09589eb31329720126e12
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:841068db454546ba420df5eac915f12727f3db08de036647c991a9291d6b53f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:53e52d1b4863dc1896f066649a4c412ffb8dc557637bcd3fe0f3df71094c2490
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:23a15ad3711090514852e9c5d82b263efc70c88005656a199c0d1806f96623eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3ca25bb19195a31a90c556718c06489308a1f6c254efdad65f89e9261143d421
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:8dee0c90149b27f27e688195d94aea3372d28484e7d0d9f948f479a17b89d66c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:4f9730d44df472004dd52b8b93ead07c7e3cb2c2a8a261b02b198815496a2dc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:1b84ac24384861830e45058e9d4a04c01a4b3b38cadf3c030453697e3ab91ab7