Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:ccb8d499ab6229fb42f21960a8603e572d70615f5a018aae40594a86640579ee

Manifest digest:

sha256:a3e306e1747fb27d9f3cfb82c25db676cb36a887c29f2b17dc23d519ba74ca9d

Size

19.67 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:022cf5e268149586fde8f6a73f8cd4d60b7b2d22bf0b4c0190f989efcbf5a902
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:66db1a52ef125aead264d393b07416b8d8393afc7596a2c5786984e15f5ccf81
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ea11d58de34b12bede8245716e7e7929f80c8762522fd8cf289fadfc30bce15b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:79625681e9119c5b5975783dae3e8fe7541f4221029e37df471ab07c8a80b825
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:c68a550f057ce9ba9c90eae3de9dc5ef92c08c904b5fa9d42df1277f87d267c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:9a860de9a1aef5fea45d07bba6e84f111991fb651b88b19beefa742f373a478c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:08fa3a5fec5188571f17fe6df9429f50a9964f8dc30ab84fae90a258065c9931
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2319226d6c8aa8638a7a6f902f2ac654c4cc30f5d32bd291c734e86f43101e54
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:9fb8fe61aaec779863d75f0faf149611acc1146e3bbef0275e8f4d88aa90722d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8f16c14dc7103f52cbfb3d3f1a3b963c37df7614551280b057679cf6d4ccd9cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c67b23bdb11ce540d55aabd9422b04d3ddd6c24f8e7013860975f8c6d928262b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5c89801afa6fbfadefac3f3e7154dfbb69f94ecc5cb399a9c2390984ca8c7ff6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:61f3f86c9173dc20e66fb2b1e6f5b0d1079bdd33ec4dddee6434657e7cdc1ec2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1580fa5ee847da10eec08342eedc5839217c339777e012f9e14f8ebf66e3770b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4343230b207ef829877892786270b3ffb29cc853db38a39109fda835491f0c7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:e833640c33a44ffa42b08274074e63a740e75d14034b3343d11e18163da188fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:8ed1a1c900a0f5ea796b4b79236ae40338e2265e3e00e784242cd7bdc6762965