Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:9242db751ec30e0553f6c316b260c2d8a409bc8d1c7282213b7bad7fc690b85b

Manifest digest:

sha256:9dc8960c7d812513412240dffe6ef8efd9c9f7b4871dd6702935b5873f4505d9

Size

19.67 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7c6e52aef699dc365005186d57f6a2935affb311be7b348e3f9e098840a36b6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:057eb0e0da3201dcc65d380614994bdafc11010e2061a2521ee95098f7a8de88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:ea3d299203e57b60cc72c41942170101ea729a870a9fcb6d2e745993de27e184
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:2ef38259eaa3fc016114c401fce12f2e3bb7f63256446160239ee26ccc9f348a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:905527b1215bac9eb0dc84b467db92ca1ceb58c763bbc76a06ca2372c9536f52
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:28344de8bf1c20a13761292b9da53ea7aaa466d881e1858d4006629bae53eb71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:884c854ca0ffd85b11b21ddacba2b2747d996cf7111529f99425607ec2f1be8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b8080d30467c6ac70dc8eb825dbebf9fb9f9934855383195c0948ef6b28193a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:16b769fd5f5f306b77c344ec09ffcbbf98b452dec40cb0040e3f25a3cdb166d5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:56537b979332da017d54b27b991782b6e452425c3fa826cbdda8e69cf0b47260
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:09b835daad1d15a76b586398b9be5edfaa9afcf0c7af143536dd03a75bb92dec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:cc7170eee8994264a28244d6a79147492422f0a72f3ed16acda25e57ecea87cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e4d79644e293d3e362cf8fd77083d5ad6acb2b18ef04ab580c13ad34c87c637b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:72a8b23c89679ed470970af4da1653cc7008afcc3cd21b67b7cff2610ce7218c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3a18e3cddba0f97eaf5231c617381169ca641ada630a2629d9a4b58663b31820
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:7197d73ce85bc65d4abc9642a189a79121fa58a8dda766cfe7d908813d88fd2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:904764fdaba30fc340da63e45dc8ac69f71f49bb18f9c698a4baea6a8e02e37c