Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.0-debian-fips-dev, 4.0-debian13-fips-dev, 4.0-fips-dev, 4.0.6-debian-fips-dev, 4.0.6-debian13-fips-dev, 4.0.6-fips-dev

Index digest:

sha256:23f2343ecb97b37a606890ca4a3a0104eca4594ad5e3ad96cee0a90524056ce1

Manifest digest:

sha256:9f769fbcc11b49a8826bd827f8bbf10610c5ca4b01d0224a59a963e9cd60a165

Size

166.44 MB

Last pushed

2 days ago

Vulnerabilities

2
3
4
25
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d7f26a1c53608048fd3750c5a2a101a83e76a442cc372c8379c1b109c8ae7942
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e4601fde5f3849ca422cc79775d2f1aabec093f456b5783ae99d434f58376911
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:06fa790d0c26e6419c185e8c5c6bcdc7630a59bb827ce518f6489028630868a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3614b1bf0014f92f8b292b1e08cb2a93e688200568f58af43009b23d3333a644
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:ff7f89e3400268b1497a61e997879f9287170eda5439a3e085d922bd34783c47
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:692f4929b1734a90fb8145938c8dc1e21da2e9bc7ce3f0ebd208d7bfce183305
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:218e3489ec1db6dd703801ca83aed55a4987e4a0e16a4e97dde7224595e8cb27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:240c04fa3841375fea306835bc621a0b79f935bf213f597561c0226843234982
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:14fbec49b1a2288ec421f3e3b6e471a6483579ce9ec864d5344cd8cdfc1cdd40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:51a7642b86536db2425ab57ac8baa554496ab1ea948c2e67a9059c3adb7ae835
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:384a80237e01de107132a8b1c0cdd7961b0d7e4b97bc7d2dfe8e56b61234c128
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:dbe9bf719550839864818442bf3939953fa6d60bb8fca822ad843c86e9fa29ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5e624366cfaf6f001f0f7f9830170853237301ff24354f24ce5f18ae381fcda7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:8cb1be48fe4cbe65332d49200ed74d83de5d1f6a1ee3a4963ca9373303340dbe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:afb9b0e55b56a86c6423fd156838e2108291a7fccf89e1f7a9a18b3b6789cf08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:818e3884ee3bdbd9001cb59b282ab35e7d22b1dc900e17ffedaad8560ed8b65e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:21fd356c074842c8e4742bd2fa07cb2b91412925b3fe00752099ff7dc5269d42