Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (dev)

CIS
linux/amd64
debian 13
Tags:

28-debian-dev, 28-debian13-dev, 28-dev, 28.5-debian-dev, 28.5-debian13-dev, 28.5-dev

Index digest:

sha256:cc49bc6a49d5da81d2682fc95804898c9523a7061c2765697df39f3aeabef636

Manifest digest:

sha256:4254d6b6b7bd4f748434be379dc2584ae5dc2d488b358ed495eb52c47281a401

Size

86.93 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:abd046c1c8406fb65a90557e8fb002a491a25c2dccf74c8da56adeb2b5130b67
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:926d0a8d62fe03e4b8709e869dd9bca5fa17e5b73786bb2b8f77548c1c37c858
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:6c157a504d565b523222f86d842c23f059103debbf4b89cfedee9ebb27e3da00
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:41e3588b029843dc74d81a8dcad589a47504780915167e695a60627bd1c3c19d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:0c07fce17ddbf543748403719b9be476d7b589e9ec92221f354403bb080f9387
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:10bd24fc4022683cc2f210c8dc0ba0095bba3f4e978afa83d32244db666139ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:ad63ef9262eb7c4dd1076c356b0ffb3b46f11fbf706cb7bd1bec7797e966ca89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:3a7e660a30f7ea9683078830f670c6c23968def185918b849f943eccb80d8b0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:588663f3a3cbe4b320e3a3d202157672fbe32fa95b670419eb11cbb788adc1a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:d41b62a8ca1fdf10b3200fb90af404cc7b8a3b0152a912d642a646690f3f5ad7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:365262f3e3108a0682f82bb8219e50b5016a44cd2294c8ac5e5a9dbb075891ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:aac6788c265bbafc7d6af9660ff7427e2b5a808a8e67514e78916ed0b530030c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:578fed4339a5a80a2d3beb07183363f870eb4db761d8a1f8b4a634ac3e5774d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:dac4cca162b6240fc880544eac61fd23d36e8fcbc968f4317357cc7ec2f97066
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:5f209f0e8e7711b3b3edf35cb55b5c84cdcec2f42c0b81dd1d5d7780091f8d07