Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:b55c3c8329d77d8c30b7ad4da31cf7e0704e137f1f40acbad3b7d8234b1c2902

Manifest digest:

sha256:011304dedab1b948ecca7db94f6036c0dda2dcda3002806144335404ee552823

Size

19.67 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d2b2c5142195bd5098838c3c1cd164ebe09c8390b28c9fbaddafbcc4d931a32d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:d863203ded9954f598b6d8556d08cadaf416133355e9655c2e4b730e7388d008
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:49cfe7ef7549b3394d0ff7382e2a8996286a58707b1e73e08217da2bbce6213e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:457c8296c50bc8de188e2e4aa4656c59e799206d4bad0a14b0ac5bdc3deadd6f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:463ba6733b4ba8463bb7a535d73301bd6ee5cafeab71fffbf7d47986256bd384
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:dafb06833860e34098201c8f823f261e6c0b246729e84f6cbe012a39e6c27885
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2348a227e4b3e695f6b0b3645aff1715d3186f75b0e7afedc004e90e639e507d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9afdb208da3a0952c49a54f17b869d08dceec51344d81bb9ab1d243bbec34250
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:9c84ccb90ab1cf9d15d9ec197d133a3c691be7373210b5d631f6fa86f78ac2fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:be9a63ce0eecc69cd52ff01b2170f3ca7cc9e27cc63161ee0f821be31e573dc6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:fee64a63334dbb5e2b3a60ea5e3b6e1a0636ec0d9e5103216fe9449d1833ff50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:bd1532f3843ae934f1bb33d25a69ae944615e2c99ad505112850d13958e909f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bf26e284c019f583c2dbda324fdbd208be2de745f99005ad0ff91a2db9fb9e6f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1311fba2594a83a5311c08cb05ec4839eb710d395a0cb1629e975203f53fe180
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:38cf0dbe866d6770364985dc88ae205e4fca3943e8d167c20a4111792fae2d86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:54786d583aa9b8e4ead65bc04cb371ab21112840efb575f84c947368f7f813d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:4a73593baa665d84436365d6f39c229ef7e7947449da01807091de6ed3ad33a1