Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:490f2fee0cf06c0799b51baa5e5c8f3fa4a65766e80b6e70f37c3049b0deb313

Manifest digest:

sha256:4dd5521d1c5bac1975461dd996f72dce5b4e2132d07b5028a55b1f6142ceb16d

Size

19.67 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a7499197caccb2587d9640dcfac2c2dc3b7ee2132680820772070be2c80ec4a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:96a1f248d18d453f42c93deea1e9d42b1e8c2e718821323d4888379bc72c0e82
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:e991b923630e335a5c1dac952cb47fea1defbf6f1d142a04530d67726259c0d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:6bd79a77709b05c755daa7c33602fd411819fc5a5c9dc2ef10b2fc5c7d735710
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:c7ea5dfe9139dbd7f8b4efa426772decb824677f0345a70c5e7e7a3643efb313
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:33770c71ca306ad185980456658075a784b1fe1c4e79060735c65f5cd0c5b682
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c6eeefe33b092a472b284db37f330bd6f722a3742ba4724049cdcb5b4560fc4e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:e90d07e9fafc7a9cc0e55e278b2be17aec6deb099be05659ae22dfa1b5d0b16d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:51509f653684076b5c6c0552d3a2e6fb8b6be67ed96e867a838d1ed8e8cf4fd1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:d15303fba416c907937da360f091a80dcc9dacf903a0367a824d3af9334cdbb4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:15473db1b3a9f41b72ba4a74d15cf9188b6f00b5b50767e872ec56113f6f4674
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:fcc978c176e268cd4999d2138bd2fa25b5b22a7a912703f809b74823a32fcadd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:69a3373d340bb6788b75f74d6bb1b855c1a1a3ba20687078dc7a0d0f6d404635
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:7b3b34157b55a12f7931aefd2831767bd04241232b6167aa3547ee894c556170
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:5cb221d85c5825acac2d6ea61b4f538add793d88bb025573e8af44288266cd32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:07e5e5310df6bd0eaca29a3066fafc4cd58087aa45b7dc511344eaeda486cf68
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e9c425d961a27bbedc8146fde58d4188ec25b4030c61597d82adbf4ce9def680