Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-fips-dev, 3.3.12-alpine3.23-fips-dev

Index digest:

sha256:a73fe1803952b919a9a5adc53d01ecb09cdbe7d2650513eb726f3dcc5aeb774b

Manifest digest:

sha256:b97084cc3f7cf3d48c68596dba1519463ca5cbde20fd3d67e89d1e231c55c255

Size

94.11 MB

Last pushed

2 days ago

Vulnerabilities

0
0
3
3
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:ca58ea597e751c6c3b14d9d5ebdc40e7d7017e8d18c8da5e09df9045040b22b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c615e9c26ae681119651d1f3fda93bef01da1b29fcc288cf72a6e07f24ffc5d7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:4ae24c6665d5f06bf9a2c0469aa30e974f8176e40c27d4776a11313b235fc136
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:02fe074efad0ff5d079977d01baa1c4fbd2de1a4381af03447f53ebcd09c8a57
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:c8ee01f88485aef6a2465bb73a607b94d35611bc1715ff0f36ede6939c869877
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d3788b1d72dc0b4651cce60e69ab8d667587c25947f45bc74cb4bdfceb10e6f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f8835ad3f040004ec311a07d0510ff49ef1513ff2e391a8dd17fed5e3aa9be74
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5046168f7cc027f40990191a9836a730578e45a37825edf28facd30cad10e162
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5eb29e8ea8ebf7ba63fecc5e6fb74aec0a31c91849c7ee763dceef67265ab68d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:4f1f1136fc3cbd8f7278acb0414618ae357bcfb8e9434a3ab4d37fe7c2d8d299
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:126b3d114852509537cabc287cc2551cfdd8fa32cb8979a019806ff5aeded381
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c838239b7a4eca92b9107cd5cb0064439530c6c340782a9a37fd2262c166c639
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:d83fc575ca84bfba306dfc7dc02d564e71379446f0cf80231daff2fac306af1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6ad8001ed9fdf323a9625c4fcf31ba1e86a26c5d6d06265b830b37c30f587782
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d4e5a80b1d2ddb08f564fdfa23f33b98d5de5e686d5aa196c1b37095e052897f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:ecbc66664dc3c3795e108e7f06f542b612b9e7a3c84d83e9d90f4643e5aab980
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b3711ec57d396c9dd66b48648cf9b1567ca0767ab41c37a24f083add12b41108