Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:ff4b41394f508e8e4060899f0dd29488d06eb499d678a56023cb0f75028efffa

Manifest digest:

sha256:f31e19379667b7c818f0ff1a9738660ecb35cd969e768bcebc1381cc94ed43ef

Size

133.71 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2d1015ade2c1922291fbf0d8b31e8ee0db776e295b5027f883161cae31e81c01
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:7ea608fdb1e45ff08ec3a34410cd845d31b29fc63f3e13d7cf098ffb1e8d70c0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:674545a72654a3fb30631d762c0473373b807614a964942677722499cb17571a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:60d991e451642b202027118e2a47aab00a06a82583b83fe9b7e2faacf705ffc3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:e16625f162a97dea1a6d005631347e3f9a5db3685aae779fb2e996df8e150811
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b0f3eab20a1d74fa1945f4a112bd45d2cdad767412dae1623b06d7b87003fbed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:3fc34973a84c167bbf129f063137c9c62215dc1b25d84d723a6fc84e319e8c20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5d5bee9c17cdac2e0a24795cfab09781b7000d922b4466d87166fe0ed855b18a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:33b9d45e1bba3cfc5cecdc62f9244038e9df69259979806727d5f37d5e86e4f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:491cae2b4771c51caff55e5715a1b02f8689ea1ceed1467519f466bed0a7cfd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c58f8477da8224ba5ad2a4bf262d748fe78839c24efb03905680bfac9bd64b13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c41d593c46a4d1e766431087e9a03b7c08a593bce5a15f97e689c3f0053c1254
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:24690bed3dacfb830b6add0a4f1907673841eb10a0cc37058bc1d676646a72f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:f379e5731ebe8e795d1019c0dac30e4413637d7fd26c01799d4a0bcc98f26dbe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4c67e6ed3c4c34edb0963b7fd5169d9307715d88b5918124ebc3164321b40b3c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ee13660f3f25cb69cb2865b29cb93e740aae11c89aad9e94ef34217ffd1df25b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9b8c05a13981cc3e02c2948e4f737906ad1d326af152783b7706ea600315d16d