Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:338f0892355f8f9b13059173b3fb88e8197b75eb268ed6b79eb92872ecb79925

Manifest digest:

sha256:4a5165e10cbf5f23b091f8c1fef56aecf2bbb00a95cf522127abafde58897109

Size

133.71 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:166443951b742fd5d4ba877da33cec8a4db9053329a59f35e9fc1c359aea1580
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c08df6a24f45218bff97ea46fee787847d527535725a87f8d5058bdc92246f76
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:2be457603552289337c25246ec9f7eb0b69529fbf0a98699d935c80805385726
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:8a6d638fa2f32b76daa07e56682d3641ef7f98613fff005b789894930ab033d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:5cfc5917715790ba1dabb0aebfdb0c6ba61c6afcedab59abe3cbc2b96638c686
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:18a3d332aff055a4c79730dafccbd3201c7744046f4c4ce99a81b3e9be3ef3cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c38d912200b2946b690f630200a43a9d9d999e4667bc570c1269e5675301bd46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:92c37615d0617db7433b07151f1e3b2473ea6f5e6a1ea7ac2d7e7f307d6b956c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:c6ec6abe90bbcebcbaa3c51a1af23521e038902bf1ec6b2bb909e6cad46e7f61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e75afb94abb0bd430ff70b798d704a46de76ca45d171cc493d16165c09050ecd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:5751abd2e962c06b65fe5aafe84b91b28f21a76883db69dfe38547127bcaa87c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:b41469cf2c829affcdf5808ebb6922bb9a8c976c44980c21ba56acec6a2e747f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:cbd191ff4e70cef9b9b6dcfccf1505df44dede5c0326b44879dcdc0d4edf0ffc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:555a8fb8ebbb984413218746bc26e500cb458b833db1d11c4a7e192d3378f366
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:d025df751cff8df32c0debe863f34cb37881235c66a9ab596fa22f8a1a1c5ab9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dd17468fb958b031b3f41994a2283b2f0818f3883ebfe25978673ac0fc85236b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:eff5dd4901d64f985e1d06a155eef501bc5a629ace470e5490bfa598d1a144e2