Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:bd4f4c549a47d99f80213da2a0ba1fb7ecbf734c9fe70927b291f367824cb96e

Manifest digest:

sha256:6dd148fcd2373a64d6f53424c6dffeae917c25a3bcbd3ad77cea9e9c8ce01791

Size

133.71 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ff680feb67988b427da3cad3b94a4fefec68a8635255cb3cdfa275f1aec2cfd1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:08c96f19317b64df7ea726aa887d2cc48da4c62ea7e63fbee1a424ba57f16553
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:39349cbd1f14e64c9424e07b2af3c40280b4c2c2bae2a8ea98fef91d3a3ea607
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:22961a2ce890e803bd22270bc15288551bbfa8d846b3d77446faa786540f5704
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:ba158eb7069726dccecb05e8f08011d7d6675ba251236235cfe69fc549269768
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f167cc1e3258f22b69618004c62bb9efce7b20b880e38f11864d00ae9a2fb8c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d4a2a2f5dbd0043dba2a0c7d4e8d86cc6f9889da96a0014c4adeac8d343dfe17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:e106bd6a59cd111e55ee56201ca866b05668375e33ca1e4300cc49933e18e895
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:a7cf6a9f76d35c54748282b47d0a3bd0fe136bd8724feba52c1bce2599f76051
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:0badb97f71a2f5b385c41a53a0005b21de0909d8bdf4b271ec81f96e6f337833
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:ce56e015c260887962e802bdd70098c39e90f1cd901bd52c832fb58aaf436844
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:bdfed59b396dbeb98913aac0e57317f2c5efcd54921bf00cab540205bc23698b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6c78fe319877a0c5052ad9d5910026b77038a382920e0a14d4310aa488b1a84c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:ed6442e957faa480fa7c923202b782e3c74dc5a3de3a852fe55e2d362e1bed03
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:017f4c6dac469b629ad6ec0d4e572d9f1f50ba0c797e4d8202c33f3b394b966e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:19f0ce0470f3e14aafc9d24793a44149a47db57ba3f1c960e40bbc16f3d135c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:81eb52e20c338249668b6cee12a82ddcdcdc2107ff86f2fc35e79cc3ee05b00f