Ruby

dhi.io/ruby

Ruby 3.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.12-debian-fips-dev, 3.3.12-debian13-fips-dev, 3.3.12-fips-dev

Index digest:

sha256:5b1226e77ef760a55dc370dee30f991ee984bd851a9cdbf1fd2cca12099779af

Manifest digest:

sha256:cac4068f1e54f6fbe939b52270057b46d9834f5c0aaf537706709636309ecced

Size

157.06 MB

Last pushed

17 hours ago

Vulnerabilities

2
3
4
25
6

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:dc0b0dedcdcc9e061e611665fc13f720d1b4af2b018203339c9fb82632e469a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:dcc861955bc5c9e4a4fb8b8687e0329036457681b2e88af7d9aa45eb58476e23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:0f4279ef94b238da66e2b885753a59f1c93e52854455927b93574bf912b2413a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:a292fbf2721d213390ab2a0a8279df36f9d2bfa6654e9af92ec15cab24492d80
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:7afb83822a89e336679d807ac7efc1592fefe5a007e9e7c7661f61be88efad06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:fa5d38bf70122a05ddc2ef91c28f9cb8c5d30fca02f01c477d36a3be35e80d52
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:8ad4d0906940b335ccfafe01e98e7bb698a13c960d0d91f956f91cfcc4f7ab93
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:d2782017d206280613fea835dff222020700bd9b1dc31ffe3d40cab02f89a76f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:74dfc26bca2cf829505e5c1877d05e9894b1c16ee0aa607ab46e5d2b66e1e6ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:5cd8f93558673f6ec80b3bacabcea23b597ef1dd4f35da9d65cbacc570f5a496
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:8ce4494e21d8e227d6e73c35eb6c57020aa5ec9a7648257e3ea8eb76412e67df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1a2cb7d20b3854fe2617a95867c19b2559063e28dbc56fe59c93aa45f96df60c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:75f83bc2c18310d438c34a02bf513d528dfa79adefa7f5c6485022c782905d60
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:76f456f1b1bd5d718f92791583f348e50e41b072ecd1df733d6c65b6623d3aaf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:df50fc5027931bd22f26d3c43c3087739c89a94bbe3a7de567490f523138681e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:28811434eddb047c83f0ee0def3a85ce55250b4e4ba3db22332c2a0643387d8a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:02a7d407382a7c2a639f3659fdb8d9c4ab3f57acdeb8b9e1a54ef53c90f85a6d