Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-fips-dev, 3.3.12-alpine3.23-fips-dev

Index digest:

sha256:b905d789ee36ffcdcf0e1c7a81696f9ed7f9c2b263bc95b8ae57f2beba4d153a

Manifest digest:

sha256:92c57bd63246c2498394a18b9abb69ba805f4aa38fbeaa1a8dbfe8ddbc979f11

Size

94.08 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7bb7e20787f157ed8e3dfeae3ed92e1307401bc57aafdd51c95347976636b59f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:6c995e5abb566c997744e0dbbbc94508123df1bcf623abd10bf3c653d68cec9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:a8f883f4cabc7585946ae27d0b36164e5c833919a442bf27ad1aacc65fe60fde
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:aaded8175ad9f9729ecc766590055a938aabae5f4352ecde0476a8bd9901e344
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:5c2d07dc18b60736aba5f082ff123a6d71bdc524e9753eb81406a8de68e8bf45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:b0c6c9e10b312f80b1e1d8785f9ce0b411673dfa9c0b28b1f631fbbcc77a9895
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:15dbb227ed08bac6ddb2357a3e4cfd18447dabaddf544cbedc71afeb8ec64cee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:aa04cbb520545ca49f7de4a23476b5774a4dc7f5c89b4c90f75435d60b925c05
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3e2737355da3a2ca096bef675a58d78c1e642f283d4b691f3044d411b3de783e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a1fed4d51d9d3c1a862fb9f9c64914e6dd5758ef1f12c3fcba5b2b10e1db547c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:2397498208e298740985803cd49df3060e6dcbb982cdeb48ed56b9f6dc6f08fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:05c8bf794a6b38d3353b3847b838986fea43f9132b3ced898a625f16a678d574
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b92fda6b04e81d35307ace772a7677bc0c5d4fce064de68af778f8fd2207c3e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:016f64f50aa2a9a732aba5771cef33449dd0c283499f78f54deb1b2a418520e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:4a6220232c103e258a020bc81fa43f61967dee61de0d987d70f5e7b68e86af8d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:21de8ab6dd23efa60c6d8b2301b2b1929d791bac8dd5ac8328744aa86872fee5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:75971790d709426069226e3ca15936b425a7837c3d1e8a8f4c23c3287b8d786c