Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips, 4-alpine3.24-fips, 4.0-alpine-fips, 4.0-alpine3.24-fips, 4.0.6-alpine-fips, 4.0.6-alpine3.24-fips

Index digest:

sha256:3fb0fa62f40cd255156b887ae4948088c3634f3ee2eb1cfad9e3161a628e6de8

Manifest digest:

sha256:67afa63de75944694e8d48ffcf6314971132ba9172298dd71c7c34aa6614ebc8

Size

11.75 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:40e023153de6a55bf0ce4411183ab5b3f26b1705672fff54769d991956679af7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:65a15ea6c47367ed21df6d6c5788d794ed1cb09d9ac2f6f2a0117d64aa0291b0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:25e1c0ecdf22d0514bce02e6ba3a2a79df9f439bbbeaa5f7ff5ace18adfd4ed7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2571d439b0d60fb704e2d714785a4f3bce041fe785a6e7ef2093b32668e852f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:170bcf90f6ea2661be830e03d7921c500d917d86c11771cca1d956db406bbfc8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4c5d681a899dc8356f7f5871f8329038ea8b5edf68f9c5d05e0abddedeff9f21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3d9df4374b978d927fbc9cafd75c9ca57db42d45bd0d14a472b473931e2e919d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:015608d28af2a36cd206ef157577e3da39120aa9a339771a9b65a01989b0bfca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9196db740f06e2f2ec599ee2af40af59c3ea15527d0a226f7b38203242571e5f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:037c603e97052cd95641f162ab9ce45b966002f326bd30a4bd4d3b046fa77881
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:cc27c21234ac5acf5a6f49c5c29813fb9f9dd7f199070ae72c5b0ac8b72aa991
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d1eab887f930189a39766edd00c8eed725a823f7f713aa312adcad5dfe664067
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c4bbb77dc7252683e944d0fbc330ca3beb68f4d5ef082a34e758e1c69899067d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:db81aa718e6967a88d614cd2b766b6186df6963dc7bf1aef9f562e861e97e2e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2d0f24fdc54394f732c4bf0f45a529911b216e674bcc1c231f9133935d2da8fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:7cacc58ea49b099a541ad7b1939bee6ff4776f22e780a6178667815f508a4dce