Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:6a9fd5472df4f8e4db0e6a4c106a2db4a2ba5ee1209374ffe34a67a981490bf0

Manifest digest:

sha256:768e38415ba8b3ab5164c0fae5d5a1ff84f2bd02b5a1f8f4f2a357caa18c0c5d

Size

19.67 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:134c92f9522df399efa78e751d72a0f2e09ef131e533d02c648dfb085e8c8d57
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e2ede2de3813ed3cf46ea86da5cdf79f8ce910bcfe899993c84618ba9561360e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6cf465ccd8d8f1725b94d372ee8ca3773150f434cbed47c3a9878922cc7ccf5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:ae22125e510edcbacf989b19809d8342345dd687ccb1780c99422c10833d30c8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:8bbbe4c9a85146f528038abf946a9fc9c769f28fc35c0a61243e1d3361b486c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f8455e2820ae9f783d6b9da0f00178beea26995ddb478440bd5e3428392abd6c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:569f74e3195fc4c0c49b9ab11a97e9c6eeb0b0238d73ea215fd81aebce8f8d64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8a5c7f7e90b809b38f3c22f1f7c1f87dc457ee0567818eff7e6435f237052f06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:bad4b3e2342ab1917782d6872bcee18272d0cdfc1b2ffb5591d10f7fd05a5dc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:2813bd89df813000c79ce078fc50e4293897238eaf779663f1ba919fd97f8997
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:513f64b53879e172547498fdcb3ee110b73e04a658677156e9683d6596c5e0e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5b80c4f318032b7d72c521531fa9679473285d2559ef8b7d7a1d35e66019b50a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:982034c169c687ea84cefe084db68edddb85e37bd97cc6cc7f2a7a06a603c7f9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a7d0533036aa0afd19c13d4a115b090951b956a6f0f31d7bd34b0b2ebc94ffbf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e9d6ee9386c8d94c9a9082843fce3313ba0edba1db3bad5552f45a8a21fa8c8f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:2b89803b5dc48604a80bb6eeb34310bef468096e7a1509c3bbb14d95525c1d8a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:84af99d9cee91bb298cbe9a92e47b1158e74dad94ff882ed1b405fde1db0b76b