Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips-dev, 4-alpine3.24-fips-dev, 4.0-alpine-fips-dev, 4.0-alpine3.24-fips-dev, 4.0.6-alpine-fips-dev, 4.0.6-alpine3.24-fips-dev

Index digest:

sha256:34fb7e2b2763aea84d5c7dfbae883d65de67bc72fa631ed0f99af732682cb7fa

Manifest digest:

sha256:18f723bbfbd1fc98a57313760f2ee146e32c560fcda755e86f412ee1035c3ef7

Size

94.53 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:f08bc9e718944277a307b3f47aabbc931293f90b9ce7d90f88a222e53d7f7646
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:14c0b35a431f288654f4658545c209874cc4e7db6066631f400dd9e3648829aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:10abb439cfc39a675786ab1a8bf0ee67419ae2ffbf9b8ab5dd183984f6df25f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:14afa7345a86253de5e38e2e5c1ae4e8c03d9be286df266cf9d2cd1600fac9ed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:9d99058d3b0fcd3db87d620de6c87f4018ff30d48a5dc23c0f37277e834588c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8c4118c3de456b723ed25c39bae2746e6128819d80a7b870cc46ecfff6326d89
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5321c662557bffeb50e2785c0471643f6f9b7678e7cf0884f889b04636377508
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:946649d0255a47b0b25b57288201702d3ea64adc358ff2e78620646cc89380c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ab0ab06eca8f0df82a6134fd06bca1928dc34c28a32855852e95ba219f5c6fba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:faf21938097939479803c2dd3e5f9919d79d808a86dbcf8126f10d1bd3bbdaac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d2dd434504ce35a0395af44cf71bc9fdae00006010e0520a2e3c5e8a2840d509
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e2b5e1622208119ee0bf4c7818adbf3a211f41a75c8ddbb51007341b2032e94d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:41154c40a26c72c579a8e6815f2430a8601b68bd5526fd509155bd6bee694f1a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:f9c2f0853a9098f6f594f6f7c5cfb9473d068ce6971e0ec3d973d6bb8e2c5921
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c8ee44435c508bdcabcd92565247aea10a84e814aff91846c3c391eb6dab53d0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:3d405fead73949540b00cfb4bfdcc8cb757503ca7d3adc30f36193c5a8404505