Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:953d522743d97963bd668c8275fc47eeb89c1f91719ada8ea54f8b2a2ea466df

Manifest digest:

sha256:bd984e501d67db75db508d7e64073e3741ec4e606a3c3242f50cc7f1e07dfee7

Size

133.71 MB

Last pushed

57 minutes ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:f66da2fc1aef99251651b32d46770619b34c4455ce4e0f308283f48235633c87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ed8a121c13aa579e5edd121f3ce0916abe8c1a1b13fe5354f383a53ac188261a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0d4af45de98f441b01b689398a242e1797794e8ce31e3cfc8e19e03c0f6c7552
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8cc90b34977924fae6a5ce834e6c104a32f3bb66d7ba8a80d7ce4a6345d9963a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:a3c202512453a6fd149cda64199c1d2fe6240efe20d4e39a237b9c993aed906d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f0a110b77a9bd41b561bda074d09ff1ca6e28f0ab9b54a566b8faf4e6bc1037f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:d7dba4b4a60686b94a01fa5ed3b8e776f742dbe6bab9d558009d35407a6d019f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4f0c278d9c74846e622bb21040546c6207d5c2d055e05f174956368ca85b1e79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ba3d3afc363c72711ccce23b1a8294c2b2ed25139eb44e58f7b65a6caaaa7c1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:beb4aaba4b0ee601f910faf54c53cd93be0f3400e33c75d6973461696e8c0643
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:f16d0bb5543d4f610572f5a8270e91d81382e8f620024e90af56f54594e3ebbc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7c0b8ab6b0b1005389cb55e71f239d00824eb659e705080852cbdbe9468ca24f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:69c0d11c1e02ba6f4a40fe78aec784194cec7c78131e5e9f7b2766624084b0b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:66cc0931cb2f2d95ce1048f0fa9a7d18845a0ca8dae56e4932465b525391cc1f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5e84991434851c529e8dfe6e3203b21d1cd772d9d92314eee355c8b17ce0f59f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:abd6ab21052da84697af8ad1a8020773f6d1e33fce967b71d03eed989c86b9bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:939f67d4500c9b72a2d520b16b4c903fd1f7ab0b0f69dad9df635664be6d822d