Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.3-alpine-fips-dev, 3.3-alpine3.24-fips-dev, 3.3.12-alpine-fips-dev, 3.3.12-alpine3.24-fips-dev

Index digest:

sha256:20c62e559c6245e252f20e7ea2faa9a2d17134e8045667afb371a43ec638ccd8

Manifest digest:

sha256:c26e33bc241b6da2c911581a73d0d93ebd71a60653ceadcb3803ca84958c34a4

Size

94.16 MB

Last pushed

1 day ago

Vulnerabilities

0
0
3
3
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:6ed39c49ded5b3b5b669bcb337ae393805be1e701d20306ee9a6fa281e2c00b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:93812fd354ffd1d95c777634ca5960bad59334d022534f8f78f00249e322cd76
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:5a468bc8a52f6777f3fb8bcc08160db3b275056dfdfed31198b815fddab04663
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8183e19b7eab86deb751efc04020a5a3e65f348531a8c6bcf35644e10fb8265f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:220a8cad94313777e51821b99193baf35aa04450191674635b6cae7d649a8089
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:76979b6ca57af8240a7b9cd6fdf18d4552368c956bb7cd08ece2b6603849b9d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:37cce45675dd502187a34cf771d858fb614e131bf6c186831267ac44906f2294
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ec541dc1780e7bd4007d59c470efbc824787ca3ee6143e1a838a9b9ac2839ad4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:45e78d9f9ec76d50d60d6b70ac6fa447507647f01f55dd86851b8ed8be01fbb6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e2fbb4da53c501e514c5b3579d6b77bcef842fa8d32266870beaec28bdbdef53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:a7ca818c26293eb7fbe62cb1c4ec875f8c635e8a5a5a2d5fc82329d3f9b2ddf8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:96479dfe32c3877a307661e4d062c01afe73e6c5eda354f4284548d71410c140
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:9ed4a137acbfda9fea6e2d3e4fb762e85ea367748417108b2054c036f1e67f7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:792b96045a52cf5334926a9898085b8bf6856907fd03b9fc58ec62f2698f76f8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d9a8800a55aac600690a77177032d4f936ce14ddbb660c121156bfbfea2af322
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:fd677916996c5a385632cd31d372b3b2e4e9353220e7b251279b5aa5aba9754e