Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.3-alpine3.23-fips-dev, 3.3.12-alpine3.23-fips-dev

Index digest:

sha256:2f288ae3b5fe2f60b8f0b7186781b071de1117f252e123bb3d93347d6ae55256

Manifest digest:

sha256:2ae34946fba0cdf672d2a93996a1545cb1ac1eb231f72ae68b1a5df3b6f9ad40

Size

94.08 MB

Last pushed

5 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:3460fba3443be1957010bf74c3a8a059076cbcc1dcc665f440911b872d580a0f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:904fab0a63f979339afe1980aa3e1afbff1cfab44a85c7bc924a0800376c7b67
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:6e5e23ca54d3f156d6bf2a505692dee70e7d27fc4ec34d5d9c1715e397c69e7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a0d296e41a4d82779b8d7f9b37a08e65ce115c05a11d3707b611f59b528ffc9d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:47684579e8b149ed99dbca7b80ccf800f55866c30311214a0a874a426b5a4276
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:2b4807f0d8f4cfd502b1452c640c276b5daaed17ce903b06d4f25a8a32771c99
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:509b52f5e52c25f7c54ad1fe5792fac9729167d644e3d702843c41ef91ca6b59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:1f794ea35c6d144edf4991d2b60c8528fd1920c002f139fee3d6635f1bd03416
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:449d6bde566df8800b053558bbf33e26f4dfabf2d29052b81c82603055b5d128
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:778b7d56813f386bd833e95b213ce214790beae9e4c6d2d2d62a4defa3def5a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3b553a463431b0886f2696a8476db63fd7c37152599743b2ec6eb16ee6d8f682
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:063575b5c0b4aa0f4ee8c749259b1057f805a91dcee28ed33a6cc4ec41b9f289
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b8a4b2c0e6e5940d6793ed805ae5cc957670b8599be79613d722f65f9fda23b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:9a57aa3eef7a54d8705fb6ba42e1b60f4e398d150a524f4b211ce29949527c89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:3de14a3236896a33f8727511a90bfbe120423714218370ac955651b23ea0b141
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:5c94e9c8c4d6186983be33c75685786fb5fa73d8ede603868a37d89e85b2c8a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:ec6366aa0822a044cd2b2b8fbdb521c6fa146a5516c46e831d71b4927b326d79