Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:bb14ab23717e4c46b9897b0447da4a5f569a4238adfea0fdaa62461571dac25f

Manifest digest:

sha256:d7bcb2fedc7af7826b52a54979d757cea54c03cd476ac40ec2edfa2b2b75d101

Size

133.71 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:edb82aa88381700dedd42c32e2384c4c93b9e5d5bb29f8be4afa939037d433ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:a136c1e9c43ece004df009f8372376579067057f549fe85fe7f53dbd6ba3e385
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:409e17d9db9a66461de790d7d66739a26e20d8bbcc68d939e997349288d9cf29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:e38f9a4c093e39fc13a413cc42cb9c0f43a5fbad49d16d423ab11cd1ec314d29
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:0957acd696a5c029250cbc7b68bef85592414e0e71f43636e93936ba0d8fbeab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:4b8b42ce77e48c08822cc0874dd9291ba9e74f031b76eb7c0b3ef5d04f0d202b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:50856222a7e3f6056abb2d9d1eaeac80289402a5397db51b52d5c9445db9700c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:a935e9ea5079a715d71cc6ecb1fc4dda4ebfe61dfb959e4b1101fd85335fa8ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:7ac9f452bad6b78b9bffdcbf821c3172756265f0edbe8c3a53ab841a9cdda8ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2598f2185bf5cd6597ef6f698b3c883355530424b50257b4601b10dd324fcb49
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c9a606a852fc0379d428143ddf7a9f1eb177ef798b165e008b39c29c1263aab3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:8e9375306045511f1452761e8daa42b85908669b1d694d8103799fd6948b7150
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:5138d78341b27d987ac2aac747fe1407c14073ff975e9881e6d834f5def2fd09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:ba8d0f47f7c34f1d7a7d11486a51b7336550157952f59ade76efe004def15371
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1ab3062f9d7f1124480e9c6c89e53f84321d25f82766cacda2ea3386976189c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:56990b4215864068b4bc029ff3a5972a8065ba099791a5958fc6d5a266f1be1d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:799026c3057d9de69e125fafbbbf5bbf8df8fa4abcd691eb6dded3185176ed73