Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:9676e9ae76c3209811af4f99ce1a131f5a7ca73e4a5bfe66cfef945224a97e4c

Manifest digest:

sha256:b2cd4d4bf80fcdd474391460a8679417f98938449ec68fb0136ee2bd3bd26873

Size

19.67 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:53b8f2a8bd3a9dd9af8de4bf618b0fc970d7fb616c54067a6f430b166851c283
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:e5cf63cc0b816d83a2dfd816fc82b49e9662f7667b3117fcc8c3a37f75fec010
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:f0e3635d5d54a7d26195fa98b7fc4fd016713f29310778dc39d10f79dc9d297d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:3ac99974febb305d23d87586dc1f5711849a705ebcf395eb72cf14e3e8c31a23
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:47bf77acc53dc716218d2029c7964f3d93a5456c967ddd581a74443d65b3f4c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:001315ef77d0ea2aad75b85cd77c3b5eb9ac96b9675a5a4935018fbaf871c4b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:c18906641426cad81886a98e1992836f7d5f3057dc71eb99aef25ecbc9ca0271
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1e1288cc42464515c7feb10594d1e95adc90be14a700a27e61266797bd4a417e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b60d956a3a037422ebfe57eeaa0c17027565fa70b795ef531cfd6e7beb76aabc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:735607636446c0ff58cc89826a88307929df431f37a825339767beb4f7b6f3f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:a3356e92102ed778be4202dd740ed68faad31383031e239bb022a5cc00831f1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1876994f4f0fded8a2cd9c4549d4ee110be9c2c810f2c4ec77e8f8e6120b2b27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:29610bca90624dcd08f565caf813bf65ac884602ffbf8e61fa53d5a64bce9259
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:934cfb8ed8ad6ffe0a94b279552e1dd207153ce62a41c4d94c43cd990243ebfd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:324338c04ec3a88fcf6772f97e5110737310ed5526c2da532eabcb45885f182e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:3653fa89076cd345471bee4784186c4a79cf3c1c529ed4a4584a3c1263354d8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:441b5405974b3911b12f33143869642d3ce4f330a5aaf4c0520ed6269111b1a7