Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:aadd6ddd313a0dc5d4a55d7caa21762bbd51bf1978984af97f62081149a9f132

Manifest digest:

sha256:006bf8a9198ef2345e784915f114008adf4d0019c912ce77227501ae53e44caf

Size

19.67 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:cdba31f538b414a1ee3ca5e02fa8ed3941ca0849e2f76eefea59da8f7c7d4908
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:0b7d5f590bd0601641c0493360f8ca5d93317b2e073f132c3a57300264d8cee8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7f0b6b6bace25ce059e852748e46778c165d81ae49b631af669083afaf270ed8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:d07c59a5dc074104f430f867d4436b37a52a72effa1a292fb173a1209ae349a6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:cff9ed8c971c1ed19b82d3f361004b35709bcacc02ef3e5b8f7233e5c461783b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:6dc39b7ce65a4995863ee671380193238bc5e818392e244a2b71407facddd360
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:15b403c586fb2ed258eaa178b5bdf2de7a1816c7403efdcde5710d907b0573bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:5a1ae7263b886a6c61e9825b76d3768cb7ee6ac471470f7b21d55d6e0fda0480
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:87bb50c860cbde3e89012ba67b631484b6d1c29ee5a752bf4f70177f59cd73a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:aefc7032687c0c8ac3153d5dcf129b73c5b3889d25fdf79565d8758d2d27eab6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3042a7d04ccdce349bcb4bfdeb964e7e1a79930add2a13ad4b42e4945ea5d19f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:9ab899e486360f5e77b4512972563acaabdb767d81b2a7a7a7cdd976703bf9a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:01078b0a2aa89154ed0e9307e64a1ec6781c2df327ac0bf4e897cde6a9f5eae4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3800b9c5cd0b4ef11b91ddcb596114e8d36f87e9722b55af32a888d5e52afba9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:0072c73fddebb99708f2822af7ff694d30682fcd4a452328b51b9407c6e74c9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:643a65fb86858d3ee80b8d1ca03b1b85ab2beb3ee01792d9ec9f9a69841cb040
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:1fc22d6002e205db7d95b50fa3c7a81198cc6d270daa5df24c7179a98251d30c