Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:bb6edd9e7b61dbbc6545e7d7d7747ac4509bf63b83ecd25fa8f04213df4b3e86

Manifest digest:

sha256:9ee674d2a35337416e0d68a878cbde14a18d4cb1a5147d6b6a16219b799f025b

Size

19.67 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:cbf4ba8eb8a4276a39f53a192f43b5cf657504848918b483877693ed49582cfb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:59d34fb4fd6db7b1681c7a9d04c0905b65a72f37455408c3357da0c5d23faf39
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ac4a003b7967a565b65cf10d95211c8721b319602b9bd1cc3450cafb211543e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:dc6e43fc1d78b0103fa835c14adbd1a5f57b49c9e0289868fc5a25ead13c479c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:cf99e0a09105c03569752a9cbed703dc242891d603ba18670824fbe220ded7ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8df7edd70029d9f194c56abfbda9476ca7eea9b98e535e19d0a950e8ac6987ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:541dc6423df23510fd99c80725b4ca07e9fe9cd59c7f0d99c02b90b0f31bb6ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:19e82151a8d1fbb9b99d30d8a7bbd4bafda54cfbea0a9fcf4b7d6059805fc2fa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:eb0ca2fc7f3edeec0fb882d963af05901a76f16f9da7241b7b0d042fd0874a3f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:1a4265a487a97ad3baa49bdefbf76f65ff9515947277afe2ea2c79a310ecf9a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:1b1944d93c06439938386a0856cb73bf64788587c91c0c9ce2803738e524412f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:402a35db75a3155d0ac2f113348ef6f13cad7dde36430759149fccc9a88a3fd5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:06f31798542d4b527eabf0379ea5e9fc20f402330c28ccf0a537ff6bf2251f9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:59e720aef47af5b527c6d9536ab5356af0591ff1889009eac90e45307d532409
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:c9525ba1a61bffeaf17106b06d31d92bef3b2722a24834a660afef37299ca111
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:d1fb76b0ced54c55945cb3c7b2f22a5fd372cd9a38b10ac9afa1716b9671f12c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:466f2dc676f5554b5a01d223896dcf7158c663c7900713db44f505e20087b7cd