Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:b69e5e6462fbc2b7a8e09256db1145d05806a88af3754f341df631d2499344a8

Manifest digest:

sha256:25f1b986d77f1786a4d1f34eac676cb4d572ec3a94ccc28079f491ef5250bbd7

Size

19.67 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:d7dd5eae267f484083b6b86511b9598edc772535804b9fd44b384415ddcbe2e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:09403c419fb6725ccf151081da5d9c151b03f84e6101a7c02ae6fad0302da303
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:097e10ef90ddb9d55c63beb20017d8d760ed42656fa98f10733d154600f07c17
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:e9c96fd78488d10f61565664a9722642396680a223d16902c6ff874e7e9baec7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:1df2f6597c68bb9ea88c803726c38a58275a7705f770a7e45d8c2ddbd8e65a31
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f099e541f49152a447aa4bd9b4a2e25c32ef7147a162bcf1d0de6359ff5f1a74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:0995b3c1d79d2e7b22eeddedcdd58b078a6d511213b85b23c139a21fa84f9fe1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:2cdbe1c9b0cb67d8a412031de2ef454f96449ad340e4c46e3126f555fdea4ac6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:f8990d89be8c1282a86cbe8c844a50bd147772d4175a2bcf14d4a618c86efdb1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:e39bdcfffc66e54f4ad106d19d434540d614218517f61b79b21a75b441e9b839
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:925dbef7f05abd596b9ca700c9067fac3587392bb808b0e367d1714f92f7fb1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9589401cd1244e1c0b3f68ccb653cd30a2d4af8175c6624047a389d57cacfd73
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ec7e9e137eca4ad1ad0cec964f03e0e742da9f2862b3a8ae909ceec6c0d8ab83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:e3fdd6e92323fe2355622eb2a07b33bee2f7129dc2269c0ca64ccc7e7e1d10bc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:df9bffac8011c2d656e8cbe1d345658e2f2069a55c0bd9e459b990e10a403e52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c4fa5bc30bf730353bd070e0a2b5637c2a3825b31c6e7228af990880fcc26870
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b85c039d6fb290a2597430f0d170b028ad79e0e3d193535046b958c6af2341ab