dhi.io/erlang-otp
27-debian-fips-dev, 27-debian13-fips-dev, 27-fips-dev, 27.3-debian-fips-dev, 27.3-debian13-fips-dev, 27.3-fips-dev
sha256:60604c84ccbe2fd664ee8ad5449bd1b4d80f4392ffbe1013ee9335e9b93a14ef
Manifest digest:sha256:c9b863ad0a82c87c39a0384ae128ab30f55ddace7c7fc37099370eb958b51028
Size
82.71 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:27-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:4a35dcfec3e01bb3020c43fd1354b329e605818a409a5844a60c1f3f26a7b8d5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:7e38f16ac98391c2c4ba9929cb3ae3f4658fae93945f7bfd13081c712a5faf47 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:3db82567ea94ee47854d255c121b10f81e72f370653d92b054bd799487c6cd78 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:d7422f849248bf9d5d0db11b4588a304433b97d624d4446b86eedb54a77401d9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:dad5f5195e88efbf090e778a4a02e07f8ba077d2d6962cb443c26a5e6ce6c456 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:6f6ef3c2e24788a1c395ad71fbd3760eed0d90451a6a5275abe5e6d77afe0ca7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/erlang-otp@sha256:518e542ade8721c78b8f487babada47beec407738f839323a0d00903ab0cd1b8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:5d4e2b8fcdbe0c4fe9d8fd773a28230636b60a6f6351f1b84510603b654cc126 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:2d9a5fb71925d37425d991273c3ebdadcaac4194f3999ceddcf4fe68ae308e35 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:6a7713debb28026a37c0f96455f56465fe669fd1c018bedd6710636212b45c5a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:5d0a9780dfa331a35a3bd8bbc24e751afa3e94110ce993176a2989446889ffec |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:54b0ac9b5223e64565a40569bfee4d9d0229500a2eaab257e3dee455093a9428 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:29c8d2e21f31f18d6e176aee6f68df66639209f57428b7805f2a0c976c574020 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:13e81e1545b49091315373e0339603776e3cf260ab0e097a5e3129421518a2ac |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:079d2b1f58841a02e09477d1a5248ed7b966f55c4cb77f59c679f6654cb1b48c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:875bd8135bc45fb9adb859f138c9488c52310cad045360732476edd251638739 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:2d32692c1ec2d8cb46a7717842439bd0b9f393b3ef1006a89f49a1350cee32d7 |