Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.3-alpine-fips, 3.3-alpine3.24-fips, 3.3.12-alpine-fips, 3.3.12-alpine3.24-fips

Index digest:

sha256:d4debbd46ff802435cf53023b6b01185473519e3faeb2412276e082baf46ea61

Manifest digest:

sha256:b6676f7e7cdaf2a77a0b535cb5d78f988de0eac989fcb41368248162cfe3f4c9

Size

11.20 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:a3d2ac3f9d24e81a430d9befba3c594583ad435fbe73686f045d9f68e7753bf6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8bd84d78acaa8a77edeb4268752f5ebdcf87f85a48a372b3f7d8f932b7a922ef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:17f878be5cbbd48f6c7571da7f7b3885ef7add9a0265586c968fe579e9333959
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:725af6fc404227e6412cf1ab2ae9b63a2a376c77e39dd8d41bb23dd784926401
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:96706b94b4d520f5375b46b301733499ba98c3823238aa5b55c0397d0723a88f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:77a7e6c5bcabce9fd233c3d3a4f2a4b0d3e6f3f44cb9116c4aa6358bfd173e7e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:3db0be3dda48bc79700bc0fd3e818dda684649483d66228b808cf2aaaeb4863d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:0e577a1508a29c33cc421f7ecfebf925d9fa9f61b51e2231880d70da3082ce74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:c8a55b4faf91307fcbe3d2e6dd523f1fb018ab1f912f7da035610bb266b6ec22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:191d09bc984aa6f3e0997245daa28aa0ca4ddcfc3890e0a277f3e4139f38c8b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:c1d567d33ee8360889f5d75a5d872ae15b2fd69f23f2648d1df4c1da523956eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:6ebfefbcbfcc27e2ece52c6db6acde988d012726b762bc1768dc59b1e8554566
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:1e167115bd26a522fc6c3a7167d0398e5b2b70eae0c7826fa0f0296dc2ea9ca6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:6c18309b96b73ec586a151bee039d76f816a8369ef9110fa8af8846c2e904399
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b9a352552baa11191ccce08d445eccf233437371fb96421362f4aed82b64aeef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:10a61ec235f79891806283c7b57abbbfa80337bef654372e8d014b1e4fb17f10