Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

28-alpine-fips, 28-alpine3.24-fips, 28.5-alpine-fips, 28.5-alpine3.24-fips

Index digest:

sha256:b89d6552b5f9f9329bc6f3ea97e2d10c430ce478a1a776e299590fb2611f5103

Manifest digest:

sha256:e47be64166a3d2b1633717bb143171328efca9d87eaee4fcadc0214f51f79a0b

Size

37.57 MB

Last pushed

17 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:7a56ba9668b1c07d59ea66067946d96a7e6b841517e1031baa061bd82b59b45d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:9d4bca7a5a5caed74e219ff7ebdcf83424e7653ff6dd48a8784ac10397abd79c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:dcaaf4e8cb39f5f85c974864d729459c199c6a5aedaaa68159932b2debc5d766
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:6e257e3c450bcead33c2e0b1bc1aa84c160142ab68342cb3d617d75312446b56
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:a715df086899d2073481b9605e62d895fb7ffc658d9dfb0a6699c9f59b965c37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:3b94404349b8bdbfed6c4bb066485d04cdd9b42a2b12ae3652cd02a4ca71e0ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:c03a4df13ca776ffbec72100830521d2c79f2cae7823befff7cac75b6061ec58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:511c02f6d51579ec3b4175905e2fdd6f6a0c329c30ac60465023a10579759aca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:a96cfa23f729a60e66db757ffedec771e66cb707ed0f662c354604873e52b641
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:bda94e8e96973369db086271cd6ee8995040aa1a881ac0ee3af2fe1cd544141c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:c866ab9a44668e4518af7dcea7920079219d06f90ce7e487e179aeb41279e999
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:a4636ee29d7304899db0d6858aafa16fa398a1f6be1b0afc160e39571fd551bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:565764a2cec615ee869db57cb140385e66d3c2a9a14ae87b4fcc13a33174bdf9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:42dec4c0bc3cad268752948ea538579e219904319ad2ef2b73870e0904b22333
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:663d3dca685a1d87d7e317132813e9ba3d076219c62cf3ed19f92e262c6dbc84
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:68a2b40e6e16cb5ee51a872f39cb9639bcf5a661c5bb7910b644955a0f2da11e