Ruby

dhi.io/ruby

Ruby 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.12-debian-fips, 3.3.12-debian13-fips, 3.3.12-fips

Index digest:

sha256:db36d6c1932061f32b57e13b4f6f394d29103e9564e93e3978b9950f1b48622b

Manifest digest:

sha256:08bd894dbbd9ee45d94574890fab3ac0228515a99f9e10d58bd0810b86fb3d71

Size

46.63 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:816a2c93de0fcc4389084a6269c7fc6edf66b79f81fa6e199baab48405133b70
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:9974f2504f90767ccc6c4ae861a16b59ca81a01bd554d2c90a7d051bf4d434d8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:b07411d7e9dfb2d1702e44c9043487b5e47e7b0d8b2db14eae009080579aef44
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:7eecb4b2943b396e5d45da910aad52a7dd4824c266f980ae6621edb916291bfc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:b91f3912eb5d968ede9954ef79c5618dbfdf947e155b53366bf3ba24dc2c67d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:f1f087d16ba938fd1e2f31f85a60a19a37fa1a30ad6e9c0a249af863524f9c8c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:cca9597bfde406c6852676d2c9e66f94be20ceb6c70946d460b1232f22cf84a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:c097807b166e10dff9cf2d7d0a9a47843f0645ab415769817a3f02bd7d1eca42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:8063d51db90914e3bc6ae00dc11c360f7b04364256de48e0f29bf33e07fbeaab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:7afdf56b9126da1c4e9866e6e104ec15d163cc8aed50db4ff1ff8a276aedb87d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:96e51b9880113f7c5c46054967f4256559c4f80609ed48b06fd33486f84da63c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:505073d995068399b71ba89a6c79961a0d66cd83d5c1de20d4e73074a423c5db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:ea99eebace8951aa9f0d9b11fa53e04b59ac17191e037a03cca4bf2aaf097ea3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:50a880864811f66276f4042742c91df3acea278699c45f68aaadc823017f3f91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:10b1c3d5228c97ab05d6f9efe506068c57d108ab2da0cfd163edd5a6bb5ab4f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:81764c8fafeeb5f96569583e1c6b5a98c6b874352721d8dc7d6012c109fa3c1b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:a4ebf64ef997a300bb0c66942f7c57840becd2383e7d963c70c5802691c11869