Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:7b7933e6d241fde2c76362f7e37f91822c8aff16e3d6060d3fd97a0874d2e2b5

Manifest digest:

sha256:b6bc1cbacd835007581c0c53c484449c605f923bb5fe3384c70bb02546a8cccd

Size

19.67 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d736210905e630c3365ac7126c732ee28b3cdc645bffe07e0a64beabdabef96f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e0a1ccd65a3fa4095f493c0209aa1363a4883a2d92e2ddcbd09637fb81a1b3aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:e074e7640e49f3c377ecf6ec28429a11c47ac30381e61d740acf66b63547395f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:b7ad6f5c62ee3baacc1877a83393a029b19a68c936fb2b47b0167575c011f243
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:d8c28e183fed1ec2872aae3412a034e7f2dacfff4257500bcafa51b83096509c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:1147e5f1b455254d001c16cdbf92fb22e9385c6c15d836110dd9fa8a3aa06ac5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:f5e64eae44bcf712db4422f83167bf535d820e3c424291dfd00a6298acac6f66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:609c603cc8cf7ff97151b205f3bec24a8733dae07f5b24451d0747bc5b973e5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:1baa50d962948abfbc0bb5a62dd9be951b97fb5bce68e4e73d1109adc7148902
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:766a52180254d329e7481c5e8559eb709b6125d6927baced94f9b76e2ef9c128
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e477ab6c789869c354f0b18efb46a8213feed1f945c53d2535aa8f04df16a99f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:25157927abfe45af02acf8f6058468977ad654cb9ca54334e19ad037c1479eb7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:f012ba18363ae98fe908cd4c0e7534079f2577a3f18b248f1d0300b8a42e47d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:cdf8ea04ae07b3ce281bc6665d69210ffc1e2b514dcd250ef1cb0ef5a2304aca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:24882c8abf154d2f58fb4a5c87da1136909c618d23637886d8fa89a29ec12ef1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:798ade3f38e6af50b6dc064cbd8e9a2e9616150837b8f8eac73e8d77d4047366
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:6692ae77cb18f9c4dba4cb12309cf074a79ec8620601ac21e35f15600f789ae4