Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.3-alpine-fips-dev, 3.3-alpine3.24-fips-dev, 3.3.12-alpine-fips-dev, 3.3.12-alpine3.24-fips-dev

Index digest:

sha256:12cc6e8cfe86231cc9fb189919edf6836ad19e8be59bc2ce7c6ea55f97102e8e

Manifest digest:

sha256:bd76557dfaba9b51c57a002e5135357ab214b8ca3bcc16c82c940e3ee0946bd5

Size

94.14 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:7351704743ca6927f47c8208bc01913c15abfd5543ff760125ccc13b18c5d1c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:8f4b590b088844f7ec6d303c8cb1bd0e340d5e91571385c6f1b389e3e03cb57c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:5fa5e71c8fc30f80e813ed36b0e80db6297e50cd36c2e52785fa3194459935ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:750b5e43c9663af76bf0e8cbe910255740a92c158643709ef0f89c8fa6852663
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:6ed81359fc73af0bf938b20bc8c15578d491fdeea6115ed3192510f2cee39b57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d1c2fbf920baa0b2330971ee517ab387b2c97fbf89074c5ef7d8bea3d06b6168
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:482fe072204d032801663d2ed61674d04a52856d860a470eb58a5637bdd24f0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:61a8676812ba31f81c7bd4ae390554bc7ae4175b593b9967cd8b41a484576591
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:a00aefd9a30c35eae0a7365dddf61aa4242385d3ffc3454669eddaca4e1eb2d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:d9fee85bede0df8b807578708735d373dcc7ea6a6795ea55dbbd1680ace3326a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5c2d80be202edd4fa5852ba0e9698954e0414a60c02f77bcb811fbee69ad2073
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bf967cfd0dc5464e76673b3b35e565d1d7f59de712de23928e397087b0e15821
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:aaa4290125de25b06f8a5d7211bfa5a8f6a5066dd11a72349f0b391601d405e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:df1ba92cc47645960791bd2ef48e661f64513c4b323368b660e138a6e7c8e664
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0064b51af3b4284aebabde74368ab832cf3338ef152ddfb06ba6e5d81c32d548
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:2906243c919954b25d73375b570b6d2ef420302f07de5cf30b0e649380b51545