Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:998f5d02fca97fdae28289a80c775df68e63524f240c305762ed1b5f996b2c11

Manifest digest:

sha256:b858a715e92e3dc0bb94dea2b2037559db6299ced955d844610540d739d0d150

Size

133.73 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:359fa9b664741c4439e308602c757bdb3ce1524fc2a1258a1f9f223e8b8199c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:046fe4c49f05e15da9578d13cf4934f83aa57cb2225d327059c8e956b529ffce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:bee707703a1eaa9489a082d24a45cb292247c7623e1389fa399873d0584cafb6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a6a79b68a160795ef379ebf3c247b6eb7a2f41d965fe6ee7db7b5511cf0aa661
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:5a937091885ca03ce86cb95346f9715f9681a33ff886d58f36231f080b12ed11
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:dada232898b8e1ad14a49ec3d1a0e4f1f75854d7f7fd6de192f4a2491e4c74a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:fbd0cf333098e34d1ed855c8c99dd19a1d88f5f049d7f8e22ac15b185bddd110
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c92ee0b1a10838c84ba3ac2c662de0e666e39463bb04ea881f99510f03a03710
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e8d1b4659e0a0c3c2b1dfe833c13f3d490cb767505dc36f6b946ff213cee43db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5fbb51224d2e0e3c92db78f3688d12e6216bd6ea8b5729495f9a7af4a4c354f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:c1199e5e55f605d228330a38a536cae50fec00ae1c587d44260760661e5b8894
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:94dc62180c92dfa39c5c21b8433cd12820b2df0d77a7f5014756e8bef6762f7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e0550c32d1ee13513b6e5860efe3d5d1c06816782c9b2f0a6effe9b9bdbf78c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:cd1b6ebf74195668d85005f4c18150b9bd065e0959c977829a355f86cf188225
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:44e97038e6f5278c3fd4b1a68b3cb01964655efe8e67c2d94a529f48c1cd98a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:dffdec8969af71b8be1ae1391fd980d6c5480cf6ec5f8973a27f335c4db7703a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:293938b4a4bb18b44c2c036688e70fd408f832b49aaabcd8de41f4d1b117b896