Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-fips-dev, 3.3.12-alpine3.23-fips-dev

Index digest:

sha256:a73fe1803952b919a9a5adc53d01ecb09cdbe7d2650513eb726f3dcc5aeb774b

Manifest digest:

sha256:b97084cc3f7cf3d48c68596dba1519463ca5cbde20fd3d67e89d1e231c55c255

Size

94.11 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
3
3
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ca58ea597e751c6c3b14d9d5ebdc40e7d7017e8d18c8da5e09df9045040b22b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:cad1e641eb9579c77990747fa5de6723c0d7a05b7bcb7d7fc58532a54b336972
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:4ae24c6665d5f06bf9a2c0469aa30e974f8176e40c27d4776a11313b235fc136
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:f7d376000085041a381983c593cf69a3360277e5932316d3bc9439bc61e612fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:8c964ba8902d0a34e4cbe434a65dc77f487665395d30d417b1fdf80718a28a94
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:df50870f7283c4ddc62f22830adf907b0078698141ebb91dd128944006af94ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f8835ad3f040004ec311a07d0510ff49ef1513ff2e391a8dd17fed5e3aa9be74
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5046168f7cc027f40990191a9836a730578e45a37825edf28facd30cad10e162
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5eb29e8ea8ebf7ba63fecc5e6fb74aec0a31c91849c7ee763dceef67265ab68d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:4f1f1136fc3cbd8f7278acb0414618ae357bcfb8e9434a3ab4d37fe7c2d8d299
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c690fa2785a32470adedcd966783cdf67696fe9cdfc074e39eaf16846effed1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:d8ecd73cba432472a9d8e0947a85b2bd7b133569e9f45b307c3dfb9b7c2ab0fd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:4319a8adc716c67013677dea79653c2301ceb959394c20e4302475d91fa676ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6ad8001ed9fdf323a9625c4fcf31ba1e86a26c5d6d06265b830b37c30f587782
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d4e5a80b1d2ddb08f564fdfa23f33b98d5de5e686d5aa196c1b37095e052897f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ecbc66664dc3c3795e108e7f06f542b612b9e7a3c84d83e9d90f4643e5aab980
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b3711ec57d396c9dd66b48648cf9b1567ca0767ab41c37a24f083add12b41108