Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:38b8b5c6515969c9d14862e4edf8a04cc82e0d2769d4827b2e2ee6302a9be4dd

Manifest digest:

sha256:c978a9e6a22d3beeaa6b7b0760cf0f26509d3c8dda6cacfb8aa270ee89911953

Size

19.67 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7588f18011a40f4e4f0d6a1ff63760b3fe6c9819d360271e8027ba81afac6270
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:64bf33d46b71d5cbc21bbcfe3afe5f694f32a8e09b18eaa07081b3123c77a297
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:8b979a9ebbd28798c0296694e1ee687a5cb50fc53258d030c3e536dbd30828f8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:eeb83cc850b4de61583a1c5ee34b2ad5cba44f05234d9c88d4df352f62bf228f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:fceeaba982bb1c79b9c68ed0f485f39feefbcfb653c1ed70e95841ef906f977a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:5ab054496b2962f5efd8fc02ae0d00c149ddb765bfeeae6b1f6e88fb69fd57d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:2ee236a625998eea7287a5f8265e93b68438f9f2dd6eb6158ae3a1ad2d94b25b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7b30466720df93963882f214595ab11c1bd2d1955a39e6734f4ac3d51d2baee2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:32809c00e52c63ae294ed0dae00356f451d984e10a395aa45ceaae63c8163f90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:9e307e84e8a558b720bbbe0f4b5ca9bd92bfb196160a0663257544b8ddc40ba8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:bdc8437138d14476c9706fb396bed7a4ef578a0fcff5130608e6a0268bdb693a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:193b39704df3ec2cc5d2df1be39e96daef3e9ec85ab902f04d07a0c2332186ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:971a0ddb6df19e47d6bb87e896ad8505bf5f590a563dba07d2fc432b92783f93
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:d105f0d65def72b245a2fe154dc9a21bd9f3009ce0c04e29d38da699a9bc312a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:e1abc29cd72fa2704ad380613fcac6f78bd79172d955e34581e71f96eee5f832
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:aa43cc3d5fa48b406914e4c18fc2c1f5106d6242f9dfc47fb913fd89d72e2612
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:e603f7fc52a2c582d28d69982102358755985cc6009d56b5d1e87f1d39e206b8