Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29.1-debian-fips, 29.1-debian13-fips, 29.1-fips

Index digest:

sha256:11a379ce1547104414cf6b96327c815f5a67e3f97cbfe8101f63476640b9f25b

Manifest digest:

sha256:161276a2b4b6e39266a67b7dfa3d402a18ceac02aa011fb444d52c3242a134be

Size

77.88 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:f93a87fa481dd9d659452db622c55445df5a576aca70f792c103161ad7a279c5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:1189f87bef2a6278d749b6437d1fda048e97fb6c46a410e792440e5b72f13272
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:b22b5ea002243515dc1e7f622b01f263ea70846504c4ceb324ccdc5ef2e621e8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:2c1b52d891deb74038f4eb2f14915cc69aeeff94fb56413eec559abd743081af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:d3f1d5e5284a41e72c9ca19620ed942cb544d5789c651a6ce4b322f8ed106cd7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:712f9fda159eb567d3ab93c804627e3154fb85598e17f1448fdcbacbf0d15d13
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:77d43987652c50118ecfae119c469818a5f1673983b89cb3ba6f08c214d85847
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:939e8470708f7fb45d50ee2f239ead07d3c0760f3f795bdaec74dd8fadfbec8a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:6642a63475f9627c0e64d97e64f9f82a505f77a17d6fb5f5006bdea1da59bd77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:4a1f10020befb3118e46aefa4207960da966d41c0b649d2d5cb12bb74becb167
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:fc00d75890194d2bd61e0919468a1d5206381d6946e02abfced500565f6754a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:dc59d998e0938cff057df002ab8a3d03e3457fda04a5e4502c0ff9faaed08968
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:10ed1fe50c67bff99a6254f82597bb9c4004b00beb2f720725f361daab3ff249
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:8b51ae9a5a73f1e3ae9bf7bfc69597ff520ba3595b1671cbecb4282b57f8f384
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:21a3927ae73fb2b1e9654c5f640ac7b1d80e2f6459196e95676d7b9fe51ec31d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:b308bfcf66a93a25487a6bc630e88703698c6cbcbb931991df16352ab26c8a01