Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:00c17010351dd071f90989a256ca0ceb94954ed908129b74b66859bf82d67dac

Manifest digest:

sha256:36d826cbc4103516fe0388f04c769d92a59aac16612b577ae3972d6f3f3ad1a2

Size

19.67 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:000bcc6ce0d6af79467bb9170ea5ddea36697806ed3dd08ae9f8c2719660abe8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:4509202d929228221f14804dbbb439e739fea47bff0d04ce5752ab3b1af6f86a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:57f9304821c13e80b38af40143c95fb53d73be0e9ad3d3f314f917fe2d0f939a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:05bd2685820d8e4cff74c4ea77429ccef817ff2efd26d124a65406deb4d1553f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:088876b4bf1c350b2d61178efbd1ef3860ef615b082a35c6f1a87b934724dd05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fc55ddb1a5d72589462156797b5ad62a8ad3bfa163bcf39c7fbed93d2eeb32f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:cf5653084f4952de4a9d2ffbd321ae3900f419775f464cc20b7ad7624dd816c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4c01bbca24dc9ac046618afda01d9fe14bb24ca957e85ef2d8a171d93c393904
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:663e87a6e9a280afcec80c52fecd8a295492fe3d9d4e65f53140abadb1b5988e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:b100751fceb0b89bd5ebacdc0780ac7dc635143e409fbd6c756a2b11fb2895b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6148c6f819045d2d06ba36e4fdb0a3c896ada32e00493a44fb53a79793797491
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3ecfd16f4f8858dfc37469d28faec13500d8b40eb2183bef768559a558118b27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:928b7beb68b8b53d4a6a31839526943855615d1595dd2aa7ce75f1a910875071
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3a48659754a9b7923704f4477a373d4d46b20516b2075f351ad3419f2a675d35
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4e1078f5c09c6a48df476ac25ff0a92657ad0551e446141ff8d5c447ce589d61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:93c13d42b5b5c548fbca62459465dd21c02251f62c1ee69592489da3bf67a56e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:02228c016dd788e35cb9e52bafc1b790b5fad030387d4ff0372e20f1011de711