Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:272e44445373359ddc1c8c05c14f31571fa8f7d7b68cc44f60c06f3d8d2d9ff8

Manifest digest:

sha256:21c2fb533bde0c77c737b84bfdb43d79fbb6ec23e78470c036cd1c1910725224

Size

19.67 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8e6d44e1b06a162eb04ee6cf436f28b2b1a13adece96113499f151ad21a8d0b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:c31bba4b2560242534d62e8594546ff8aaae83190518ac2d22cc4ea1b57e2075
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:64e4015486b1e402f08ec8bb6c7b71e508d0cc3c2c208e7b2c692cdab874c7c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:52bac0f93abe930f4a78b48ea2a5318912087799d171550bfb764c3ae57c2777
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:6630a5e62fef43906bb268107edd350ddf225edef7b459eb3a50eb2437d1ecf9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9577abc59a86263a2b2cf817042d9d2a7440d4815bf598c5f22e2830bcfa100c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:7afdd47d226048187e58ed116b4541a02d6a7f7f56e09d0311f06166c4be268f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b4eb5b7b2b63e1db18d46417f056d2bd3b8448e9cf5b964f8fc05883957ea275
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:2e0272f2a03f7c0bf624fee014673d3901b1a3abe61213608702c0ff33518fad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c4e18444792efd4d65f673743e389061069db3a2c639472c81143e551ce69add
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:17714b0a6a086daa82c5ba3be90e591cd39eef7752e7da14d6c76610f9ae4611
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1cfad0fe13b45d6b86fc4e064c1120924dfeb7a450442671e9262f3bf3b5d8c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:81e0230eb81ba2638e994438d049012c0f6232ffc74da95e254013c7cf614467
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:a64fae282b4dabecc9d1d7cde770f5d6b6671ff621f691a652da1fc5cf1fef00
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:7e1e671d2cc907c5a16643513a0c6d735a35236720be91ff3f1eb769a9a31afa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:70f8600b4947d2f51233725bc603eb7b5318b190607f8a4abbc6944d4a67aec6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8775aac05ddfa044ecc1e5aa0d99ea9869c703c643808984441721508b0e1a4d