Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:cbbc2cbfc6b373e17ef1ca7de6226f3c92e9332363da581626fe387d62411108

Manifest digest:

sha256:5ca5cdd556668e2e4479f9d2d181ed00b1468ff7e846d29dd54c557efe2a8992

Size

19.67 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:415ac33d01603a3182e35177c9519f07dc7f79046ac219f4b98d1981598aa1be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:52e93d4cd331c417c8c721153c0b7439a094f553df4a85c495755fa005aceadc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:51c2fddde1bc197b88597dbe857eb75de18d4c0b58ac05faf6d09abe6f6c3ef9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:58c3610dbcef4ad81d509e79f703f71a67b7dbd409a039d91c63772f6ed7ceb1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:84d3be01ea8ba5067182bd7541f52322e4c2eef34ce6bc71caa47e73e5792725
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:74f581733c6b7c8356d8653e3038f548cacc6f387bc4df3c554fa4c0870d49a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:bb993e2306eda10e11b8058843e3ee5dd8ca3cc511155a3b1a0b8304bb64ba0c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:dd18bb98d7dcaddf1c89fedff7dfa7887fea0eea29e1a705146e10fdc4017d1a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ece597821ef72cab98ad33e247209085d052a0ad12194e0b92a8c68369039a9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:ed011e91f96206a82d337108efc37d39623a996a5959adfecedc36e3f5a638ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:da5953bbae275a1ed1d19dc857d6b38b49a7c30089f3c3c57a40bd0b74fab932
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:20cd1b0c80f3d207ebed3a22bed09d6c898562fe79fe9d62e7b33035b251c100
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1ae6ed1073102d57ff90c36ad46d3803a805dd65883974b42955f5e82bbc3b3f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:22982f95879162aed0e2dca400bf626b9bdf97831f00924d1457ab084588efb0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e1bca98c686f26e39d69b789581de7d062a09bcb68befe6ebfad1ff1cb0d3693
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:787597bea74676f2bb19d285c0026a74cb98036fd7e00931bf8e2da31e1a1ca7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e9bfe7a4a8e5b9e251fc911266315e9c86ef7ca878d2a1c7e221951a4357a30e