Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:f22e1a9c728c61504816daf64f68d2ce6d321abd1e825a44af62e66222a59440

Manifest digest:

sha256:e2a047b80a3ef4fc9280c35a8ffaf9fce10efe150c710d8cca5d3d86152bbe05

Size

19.67 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3df6a82d3eebd23512c582e0944ead985d0efe08c525d1b5a6268dc84674ba09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8d070bf6227fda3cb188d9f4161059fb5882e894199de8bc7ccc3c0aa6498a49
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:e6d339bc340cf8ed999cfb0da7fc3fa63138961484fe74cd184400863e7aa978
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a02e6bc72ff088ad8a87ba358a314cbeac0d81f297d67465a4d67a4118c312ee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:a06b747cffa2f1f24f7e34f1a6f8f5b649051d09e99d5fcbe1b3e44c6c80ea53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0c19c0d26bec147f26f157a1d54dcb1804c6da0840fac29caad310ba6ec81089
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:717cedc854bdaa833d0c7f6946c9d1fd46ceaa9e2f1355b66057e89e81fb217b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:7858a5e3e1b7afcf4c7e994664db982415051f0a205761fb71b0707713e35ade
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ff2cab90d9b10542f070a9ea3cad199b7f919c6c745a297b39d13e6aa4460c73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:326ca16acae17e33b641aebe437e4892e4e54efdc0e110784aeb93a07ad9e920
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6bd640ab211c58eaf325c0747650a44729ef7f77c82b887081233f6294d4281d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:b231e5f4859cc33f90e2c52c77138100eb18c23c0954228714f271ceeadb13b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:1768c07b212310f41cfa3530fd3d535f2473e54e245c6024e55dcced514cf852
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:cc7b673691f247cef2e3bcc62e72ad5087f32d75e9de0185555f7c7bd2f13c3e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:577eadd81bdd94caec48f4df8c485f36a32e30514e19c2ca0cb475c028409fb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:c15df11f21963b0964d059b54de4535a0c852b27b2eead2260ae64677c772d4d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:98625e81d980217e9968fd14e7ccd67fc16497c9abbd6ee7ab324ea29ccb23da