Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips-dev, 4-alpine3.24-fips-dev, 4.0-alpine-fips-dev, 4.0-alpine3.24-fips-dev, 4.0.7-alpine-fips-dev, 4.0.7-alpine3.24-fips-dev

Index digest:

sha256:a24c216687c7e49d227a46acbd60c563ee5f3522783220677a7b775606c3510b

Manifest digest:

sha256:76a82ea6e44161c1f3598835a2c8d5d8a679b85bfe477b696ef992539f3086f5

Size

94.59 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:0dd3c5b580d436f70afe31a80487aefe5b604df54e6e5f04997be7810649625c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:52af417d340c8a5050d51a35098afe58126509e3cf06e41d80341fb392200ec6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:8fcf67a650825fffabb5d75d1eb7c62f3f0f73df9a7d9ca4622d23c388a3b265
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c934688ee79f86143a039c6dd4b07fcef283b8134ea0b5e2bf5ce957ff6fd3b7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:7c7c7b33225139a42909933bd2ca17ef128c9bec4e45a994d001f9d086d6c06f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:539300f34442d57f04208636cb9e86e3bfc98c367e2ad1685091632c7d61622e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:24f1c729ed22d9283b93eaadbd0b9320118b270adff2108401cf4ddef7abb139
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8365315e19b8e8e1b2c8852bc2deaaa5cb556ae1e7db1e5253ea865f5cfab735
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:eceb476368dae2fb0935d53e5e379095131e88939743dff6017a06651ec9f1fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:72fd5c15c2a34a33fffe2c8f8b39b0f8c5ab8a7f88afd82c6c193332e089fe3c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:2fd015ed111e24959ad61a1274f89c614dd6f664237a7b23e6ce98666ce5916f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:97c5db36247a62f2c044860ba288a6e4b2b5314de45c76ea185e354c03e1c727
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:9a07b7106e3effeeb0319280ef78d8c98b4f801e5485c5da4c9693ef9c28b8f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:9635e65901f1ec3def0c1cce46d11fb4043302a571bcf5214091159b2e020fb8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:18b99abf25e3cd9fa25c0fa637ed4938dc3886bbd6d17a95c515964a346c7f29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:d42a510be949091b8ca7ca2b1b08d0e0db992723a7d82580412f558e608570b7