Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:0a80374ee32c1da44ccba80ef32b025b5d13621befa8d28b06b3f118603cef48

Manifest digest:

sha256:6940ac27e6c2ac4007dfb26761f525f7da6ba9f8135fac6864710e300c722fce

Size

19.67 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:424a9a39f2dd72cbd97bd16b4ed353180212933037f4827cb587c1a360776b39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b0cc030ce43989aa2b769daab0866b7a0d4eec8675deddc0d12ac67f7002a0e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ee4f8a74d01ce8df29daba99f34020994795b3627837b6d1461f6b8e31e71688
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:23cf002e863e0f00d8a5756f93980d86c983feb8f97fb657c46f6899afeb34b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3e2313b471779a13d362d989a17cfb7a871ab05f45798fee1faa787f8ae86565
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8ded541e417a9bec27e275e61c4a4d4ff0dddbd11f45cf635f4282d9773ca945
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:09ee644f3a71de7465a372840bbe59d76c71616ab330ae996da8f4d375153664
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:bda992ba2b0429b0a333b755810aa1b00a0b9efadfbedb3ad47fba8cb930c572
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:6003742ff8d37f40d1388474f1ab3b5981483c75447b50f56ff0bd96a41627fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a9227cfacf869929e8bb4dd494715909b4aa8d24221f52e1351b6e9c767d3b76
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:138910058d2c0ba60bfd9ea5945c4ca5a3f2ff48f553e4810c213f4b11495201
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6b063f6df4d155f3a6ca6bdbdac8de22b47172074b174e1ce7c54141a74c5190
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:88e7cb54fd0f72601a4cdd0086bdf040b8a4da59189b540bc282dec46d2ef62c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:6a249df03aec1e879340f2bc1656b7f87f45e98af5703b24904afa6d39c20bc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:98e260d5fc18ee63f8128c2b25a38e387f42796aa05fb0d2426a6e7862713da5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:afefec63bd46372167ec96dc5f3332dcf15d973a07df99f6f03949b1250037b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:9c17e0eddc40e8e4d258a3f588c59c7fa6547ffd30e5581ed61b74523cc1856a