Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips, 4-alpine3.24-fips, 4.0-alpine-fips, 4.0-alpine3.24-fips, 4.0.7-alpine-fips, 4.0.7-alpine3.24-fips

Index digest:

sha256:4fdbbb9f9ff38d1299bd2af7e2ca252e39b25066a6a36a65330d49da94e36abe

Manifest digest:

sha256:87bdf2a5edce8932dded1901cd8ab45f39c8fafd1d2d48375b9796694c859403

Size

11.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:4982818559b7a17b83dbce323898613773b671304b6106dd776e77f54ee94d87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4d448b3615a2c137b20133aaf27a7e298ecdf417a360a99cccabbae7170fb308
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:84555bcb66ca8adcb43b09c808d8a9ef110504f7cc6f2ee176152936767097c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6e9aeddd569237b9e2b283aa8ef55433634e3239039d1cdeef19b2b007547609
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:c674a6b5f3a8dc1113bab4f5deabbfb78e0290f6ec59af94f42fc70957fcc4a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:c66240155d1d9fbaa297bee415626fd807b24d271e7e55067040a3b68070ec65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:56617fc3a68c78deb22acda63082e0b854a9e19a4c991ec1b404b1a592461970
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:d7f5ba8df230d797fba6d86089ede1aa2d7573dcb2ef6450e55bc65c535c6fae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c1ae29b50cbe37925f48b39d6ea68defae1dddd20faf090829392d2716b68235
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:29224dfcbf779f3bfdb18ba8b83863d3b63d66f96d51080775e73070a6ac488c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:689aa19ef78aecff1caacb6abfa4ace4edea90db67dbb2f535ebac96ee98144e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:133459a4744e3512ad36aaca9013678d7c2c4c33034da192ee926794001b981f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c92e4316cabdce6c49ccbdfc70e3aad9d794003d547ca7f5c654ffc78708f967
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:078fba129d7f57330a79045c3b9d32c92a8a751a98f9a148934b3a72c08a1178
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:f20ba82e4ce842ac4a95537419bdfadc4daf01a543879f5ca63b0a1585594fd1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2fa27b4fd947bc5e953c76b73a9bcc442fe3ac05a814d8ab16ca7ecb2cd3183b