Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:bd002f4111346826aa30fbd36f15353ec91e09cedff58b2e3462673dd4e43a12

Manifest digest:

sha256:cf0868240ca010982eb6381eceae032866a9209e5cbcada9eae0893bcb25ec0c

Size

19.67 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5e15e057828f6f716db1e1067e4836ec374c8a2f983825ea7fe74ce067e22e63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:f2c665d27124baabdb66f861747fab569415e8d89a91904031190502d8299113
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:41c2bc7a37377f194d4ab5fcfd3d575e0d3d9a6ef6b66a6e8a24d0e6537711d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3665879c56529269c8de4db6fdfb91089f407c161442c33d5f2c8567aaa5dc42
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:b6c68ca7d7eb3f877764422ce31ff7020099ec09d8c99ba4a55c640bb6e1f340
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5751a05007734c9ad3d10241c69ec69f821dffe82310912b11f8acee1ea10fc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:4f0502db3f7c9040dce3d441bc6f68f51d0fe704881b37d0c76d964d1e7a1f13
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:f46c7ad87fa980b0bb34cb3a91bca2644bc8e936d594fc127853eadd31e0e426
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3d4962aa07a96ee8c5e6a613ed7b32fe3d5b5d1659de9cd5937e8877f168feda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d1e2df732a0fd376f4bf8049bb3b17e5cd1e11e0dbcf5f4a8a49376e991a2112
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8c17a8cfaa72a6daa0d8e300b9f94c2d59316e5fe82173ff7e39de437eac0a9b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:3f4e8e7f0a6a42e7af8c10762af9d979029aff6a2571f792b83c48c410dec376
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:0e3e19d3c86092946713179213e389a7f0e3223962e11c225fce9436833e781d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:03ddf9ef9ab02dfe65899bf9a3cad8b7b026982d7721e337323a6220f3a111f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0b2f90c569470182978d2ca00a593810c2bd640e3ed72d92d90ad92c369d4da0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:60fa99bc8e4042b702d6c73869d464e72a5bc0d0a2f3ad0b7c1304d2cb41a285
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:5523e636aeb7c8b159f0e07e8b2eb61447ad5d56048e2d32fcff48c3350be74b