Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.3-alpine-fips-dev, 3.3-alpine3.24-fips-dev, 3.3.12-alpine-fips-dev, 3.3.12-alpine3.24-fips-dev

Index digest:

sha256:ec80fde27334b4664ca02566be58b01e934f27d36a2bac84925b8ec464530bea

Manifest digest:

sha256:c8fc17f0cfe24d1f7f785e853fc8fb33d9b4cd64ca3d2a59dba5350f83e9820f

Size

94.15 MB

Last pushed

6 days ago

Vulnerabilities

0
0
2
1
2

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:5a6d95378e8af93c914d230d7aed3e99b476f52a12d9542f1096bf2c99673125
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:1ddc478c0479cb8f0a0450ce6403ecebd7df362c567c906c9508910fae9ac9d3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:b6bed3788357dfaf82d7215835591dc00a4d27547f64ed14bee0cbe7bdfa63bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:952b70b417d6e749fa119a5fa668ea3900a3b0a3015aa053072c47916624f27a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:7bc82405f198fe356acf3f3bf6acb2869064f1ae95a8831cb3f61a5e9f9ff477
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:0abf2c8afca8c1e6424c1a5d833ebf1bd6a10b24be4130c4d5787a4a16f0f330
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:b10ba273097266f544cee4b3b86c31e85672edf8149c306e80a520c02de6abf3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:6f4d6fec8800dfac0a149b2e129743b7da9f48935c80fdcd6aca0036ce819f92
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:53ce74b8e6e4db7b1cccb4e4865fe288dbfff12ce9eeff442a4a4d4f7508d95c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6a06754fb389345fa19eeba9c9dbbc7e5e7ea5a0ecefdfd80fa2b881b5f0b025
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:13952b2e09db00a6933f322bb368a291a2b4075e30010ee70c164ecffe455ed0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e37f8a71b338f7d74821ba0129d4953c0138c2a23acd5a15a059362648fc3ae0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:21f0ef44f68507e331483a2599dc0992f49bdd07d16f4afea41a7ddb26f0a9d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:a4b966bed9a971b3468ccb7e784b5f4f553c982c507c6ee769ff3c69715e1b7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:a20320fd0df1d8d0721a9073f4b1038241d568abe958d61054e083332074ba8e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:b847dbfd3eddc5bd5ab67a4b9fab37aeef119ebec703ae6bbf87258d4c6e25ce