Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x (dev)

CIS
linux/amd64
debian 13
Tags:

29.1-debian-dev, 29.1-debian13-dev, 29.1-dev

Index digest:

sha256:445b019f8aa0a4331aa44d7b3f957d069c9d13def4d71e8529efe62bd6c63ad5

Manifest digest:

sha256:072f5db1858b24f139176834a5d8dfa50d37d706f85b2172b48e8c0c3c81f716

Size

88.16 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:7675180e26c76e02e4779782c3c6b947c79e492a1119f54d5c94e5efac51720d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:70eb9de018296e590ad0cc2ab51031c4420b2aaf025226a672dcb825da742487
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:737f0d3245f01914b9af036355d6c89b33a2734b94cfaca92e73e12975d7dee2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:7028a31280d1becd22bdd9f4b5b987a9a8e0e978583d2b2a84764f1790afa030
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:4f99eb90e3863380e4e8e86a2fa6c99ac17bd1899dc452ce19393abf8915f644
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:ebee60a177c0dcfe38afcc1fc2b8f85dd1eadce263aa16aaf0e7bc82bccb1df3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:77e386167020498a2529e71e91b5a4c314a21018af315687f93988c6e672de48
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:9ae02ed7f65971cd23f14f344e63ec8bdf4265f6c78cce7c709a0957b8498c04
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:36ac13dd21d019f43ca394c4f97894a75eff5ba9fca134410fe0cc56f7b0f24a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:c2f8ecf5a641964ca9c780fc1fe63f7b5ae2b943d128f1b1f126e0a3625d459d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:8e7751d05e6f1d0afacff2bb3eb19938d18f0a954b2ba0482304de1837f6e42f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:09e85feb1203aadf97190d65cb5cbdd37d6432ceff54ec75a36355b9ba2dc46b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:e35fcb49660379c3eab089a6b675e8f1b64922ef202027cac2d349b9b4449b28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:19c4588c2b159e2e9101d3e7af9409eda3c6b53961e4a51a61d113f14d2777aa