Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:1c4e7ef7cf7803ea79603d33e340ca313f2914e71f2c2a1ea6598651679aedb4

Manifest digest:

sha256:5ebe43096cb2bdde13bc554c60e65bbc829348423ceeb9e71ad718abd2816f79

Size

19.67 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:28c7498a3865aa5afb5e3234d24251954525c8b945cc354f7f49ed58c73a37bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:67930a3636789145d7345e18c9da528a63fe685eb13c072ac230eb444e03c7fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:db0344a407678c3a4a7a2310945014d96e8b8d87267b2ef1ea5a73a3f7eecfc3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7cb63ec0fcbcbd1ced99dd5be40cec7b6cb13dc47e0d31f1e01820299aa1a71d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:90f036858b40363ef3f144f641b1d12ecc083e7d125e50ef8003ad6ae3238f06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:e643773806ba8a1f431c1ee95b3685d60b95350581cab9b316a90549a81f56d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:29252307649803d2bdc98fb81279f936ce99cb6ff500975039542d4fd3c18b80
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7043c20586ee9612fd2069d9aa73b00d0b3a23358accf95d18630224496f6504
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:5a8a5b9fb2b4ccb37677b8ce69b16c517141b613211eec3b1c93010b84aa157b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:904eaadda01568e8508175a905f58d4090a8a3959b5aec141cefbf556ee814c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:b3fdb1e05eb7ef382fa180a680008daea25c55e4adc251ca59c0828e4afc28b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:545fc287b54c00acabe6a470434b9db7e578c056c619e75b49113970a2d19ecf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:921af9c3ab7a77a3139f91caa2c2f942bd295553be9796c53bb7b3687b58d0a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:c4d822cafdded8c39a2eddc75cd6ac790dc1897d76cdce2e284f24558cf79377
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c5675c560dad86ef5f4868b8502d1e9626a877dd260e1c0916145f3d81223e52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:afec35b674326a28292452660856024ec9148f0b3e3450f3988a8f9c9479b6cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6aec1b5a73af560c40bd1855441847f09957b74fa0a007f5f0c3400121c39b5c