Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x (dev)

CIS
linux/amd64
debian 13
Tags:

29.0-debian-dev, 29.0-debian13-dev, 29.0-dev

Index digest:

sha256:a5f4de90038718568d71d126476dafe482b76424cc3c35473dd021af815a9e64

Manifest digest:

sha256:8dee2bc7f88db2cf0c6a8370c2e4f44b90dd663179a3470502eae544aebc7d29

Size

88.10 MB

Last pushed

57 minutes ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:cfa18a62f0ca7c6462c7c496c07cec6d77955e114caa5acf9591d2bf769692b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:c90196cd9823a3047d0bd90cd6e0418660ab8c4cf6a66e3a43e436ca62bbbee4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:192411fd11f8eb726ff82fd2aa958c45704768b3f2fb983c00477968e5cf834c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:10f2be8ac98e95e6be52680531e5302165237e3f42e7497ec8cb536cb12df9d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:956b1062ba9e0a2b39741a1287f684fa7df32273f29fdaf623894e3ad8eeeb69
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:0d36ef13de187152202cec2cb64018ee3e0df7be55b0baaea033074d485c3c91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:400ade2b06888b37ed9a13f1f504e8d9960be694e48e05c7aa181ebf5eb4f49e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:dd6802f5f631c63c32cdf23a2481b9e89afad3f2dd20214b9cdba6bab4ae11f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:71eaf73a40231762610b49f1be4567a004f7b30f64360d3397cee210b0396493
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:4e4eb73141ea82a61dc82cef337361f5b652d229f4959d08db0b801031b82f70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:60fb1b536bc65ab792e158a99758b275bd7bac1ad03c37f94658474b2264ae45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:19e8b183bb9fe2756f84ad18e42e097e3d19a2fd51045e286691fab39adf4108
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:61246d90f229a405e1df73546950e6deedab1e3c71d4bf7bf8f31166917e243e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:d5039493403f91c2f7b46b5cd6dde554e11c0d109efba4cad269fdfc60804c58
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:78c05f0d38a1588827b07d595c367080e94f6c23cb4d24bfea6e6b96b32cd29d