Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

4-alpine3.23-fips, 4.0-alpine3.23-fips, 4.0.6-alpine3.23-fips

Index digest:

sha256:e62b59e83764ad87a1e45b26e169c6acbb6aec6adb67103cf13adf4a5e0f11cb

Manifest digest:

sha256:89e9831d0962ba67f94666815d7dcff6d1d4da3d8035f8cfac5c877470dfe0d0

Size

11.74 MB

Last pushed

13 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:e16fbd27c0ab5d780b11e6e275caa228a3e4e48e591d31e78401fefe8a215d25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:22915beb7eba5c5c3b1152f2a31241550d360432fc32dedeb4068203949526c9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:db914615ecf3bbf6226ad1113196c24aa0a75136fc58237642edccaa1ac19b74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b009a469530fe5aba6b7801130738c1e46edc19d27e5b0e114bd2e3f24d0206f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:50b238f2f3b99104a0c2bf927b7166c00a711e497c6d22c3a4a8b0d3168fa2df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:3b30d0d76450d960f80932152be1b10bc2036356a18226285f48e034f56023a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:73227036bbed6a8fd2f7ebd39f198d04d41a2b3d96486f2d708182b30cb602ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:93c59138c11e3ffd07a8d6315bde66322e7f83be6452fe198e5e57a22664c747
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:fab429fc809e4ed7eca086638286115c1ba41f62173c4d9ee505bf34e655f1c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:752d1c7a6e3d5dcb3b45430ca46917e007b5628282c078091e3ab3e489bde34a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:bc7e365180948fb554977d32b64db197b7395ecf8954f6c18f6701f1799f6586
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:e5421ac5fd7ac54452c1347d3480e2a014c3b0d0ea62edb9a74d22d4cb0e7424
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b980920b38ea7d629f9a1ae418201da2611961a20eff6876efa4b55a6d1e9cfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e5f0f7af1d56b3e554712b7c993e91d6dbc5cd3ce630912c565876fa12f348b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:ce673006956f43e5735b650899a4e8755fa14ab7c7f1d02a5d6a648b58fab3df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:21618aa2fbe71f4e3076a52c0de40595621635bff52fca119a9f4e839a7b6a45
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8d4c84807a8e7ffd831b1387b575c2598c74d3269dad48ee998f64da5c33c059