Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:f56f3fa90c5910a6bd5270e2fe77b9512e4fcd839f618b1507efd0d254dec933

Manifest digest:

sha256:afdbb5f95881a08da5f9adc4356c3eed5680cc656e5fa0bf2a3ef649b5612749

Size

157.03 MB

Last pushed

1 day ago

Vulnerabilities

2
2
4
24
3

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:506910547326c7215adee41ed25436333ead59381dc266345daf7920b162f857
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:85a7143dc9f1599775660e7c1dda11a6f6b654f10052618b113c33ccc02521a9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:f4706764598caa071ab5f994b587042b25de105bfc4d13299d4d14ed45c1f4bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:20ae4e493d617226ea121451db5e2f270dfd5e15d024b65d8175963062a50528
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:15e5d333784bb28823c3fea688e9a053a7f00fa42b83a93ea249c51a9395e288
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:2cef23bd0f0a786aaa5776c68b49cb824fe19e80dc969f8094393aaa1366b627
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:207224621ea9cf37eb117928c4623935fa42636fac17094d2e970ead436b8bbb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:4742c6d5af805d0f5ae7b5b34225ec3d96defcd87f6fb7d253dd49d4bfe7f0db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:b21c1450255511d5863728587fab11220bc30cd340c59f0ff1f9139bf909ed14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6e308b1216c29db20647cb8b0d6281efe73f24014db23e5fba960966ef13b3bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:49bcbd1a7fdea0b67b067a26e4b9eb2b884a41531064998f3dc12d19b37eecd3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:5fbd341160d58ac79b6df8c95851767f944bca439678e11e06c6aacad51c4304
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:bf32eae5531a7afbf952162d2fc318d90309016756badf08179e7bd998385cbe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:b193ac1c375f9e01207db47c322cf024cabf06cc87789071e0c93134c42f5357
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:951810336804e112a259e7e40cb9f5877a04fd23b3a7fcd2f7e68aef55c98866
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:b2d552966339a706d1ad1857189894edac41379a4b0333a9c9f32c7bdb44341c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b9c2cb2f9bdc03215477a8a3213cd6745eeea1e6a7bf0e265772f8364deaece7