Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:d32264e4d9ae86783a97612ff12343fc803c38ac34cda90902f00a46652f4a7f

Manifest digest:

sha256:a8d104075bdf9e24073534a1a46462d54ff3e98a55695bfceb766f4dbc9ba6a9

Size

19.67 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d79e957a0f2cc79acb83f7d2e1a8224920c78c8e69e008f16e74f9c6ff339abb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b05e75f143adb8bf873052654f7fc88b5343ec79574ca5a795f7db7ab2854041
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:78265c3c5d0512487829de76fd5086d613a2da5dbb4b3fd92ce729c0c997550d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:ae79b8c1d42d2e11d62a0b2e80866ca97c49a5f4777e6eed2e1c807fa3653bec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:28d0db75fea286a1e5e2f4af2d5f5b819fb083ccd707daf247eafbadcf3c15dc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:ff6371b5805ec6eec6572d95f8c371ad6c3452422ebf49c162e1c9e142773c9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8b9538380afc2a298df5779e10aa87f29e0f0496ba79ac8924f8aa7e932e04c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:550e739ce9ccbd9d7ac121037f4f1570e3dd5a560023bad5c8e2a248dd19c0d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:4c422e3413aadcd2329fa4260924334fe22e6751e74ad3e56501f5eba457cdab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:97c69bb01dd67f38234f0cebe7280dda04475e47cdb78c0ecff4a0e005422f8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a37d9251fd5bd4ba3258d43d0dca12b8e7c7fdf40976d97a7b3ed238fbc97c0f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:7e07d3ce239e7a52d205cc1f887298b261f01413359ab11e280d72134eaf266d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:dea7420e83d8546931d50f80e520680e2813506ad92cbffa32777f78e9c00db0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d832cad4808cf50d4322a4b07cfeb23700eb5a278e9daab6ad3dc6f064b92db2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:1d13bc37a6dd5d39ad7a821f53d9df8f7c2ae4fe6093313563a7659beb8a3751
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:21f39461ef8087a8a4e8df1a46f1e73bf8c54a51f331da6c2ef0ca128d63e9b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:cc103c30f1ce61e9c71d9bf73ae5815cfc151c790b6862a9b0fa64c2d84e074e