Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.20-alpine-fips-dev, 1.20-alpine3.24-fips-dev, 1.20.4-alpine-fips-dev, 1.20.4-alpine3.24-fips-dev

Index digest:

sha256:aa89dc251e35f312171f1d3d01fe38124bd7dd489bd72e5c5f8a369c0a9d3331

Manifest digest:

sha256:d7a1dd6d322e1980ac70c90f23431510a6d8ab9725344ac282746c460b971e85

Size

46.07 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:145c7bb747de556ac8f2093ed41efa0a08dee4c6f2fb5ae63f63aa1da5105c2d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:69c8ed8c89ac816a0c92d5c0c634b337ad3b5495c25123b259bef85b0b14079d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:1caf229ebc88f8f22f3aa69aa4f5834d40eb786cb532006c5af7d65075b317b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:b4529f09113a18315442ce36e7d3c3a21103ee7de61069c3de8fe873916bac7c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:fa20c1c037a866b218d6b7137fc2f000fde2f9238083d696f8b7579318bf98d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:70ae5903dc7f47c26c28dcc3c2548354bf20d50a36f47bad84993cb7efb92377
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:a3a4ed1be19385dc9678a4453e77a14bfdaac30e54a169512976d2803e7ba54b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:aed7f39c93597483ef8019e2b20adee631050806e1cd5e546c8957810a9c5b87
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:c7a930ccf0e4e3582e0ff037a8c78d7dcdcc0e15524af55a382cd9760ebfd8d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:f9a2a1ce55b674076f2d47110b09278ffbd11314325515b764678029c4ca605c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:317f140153dd4af250228cffb67a07b1ab961d8a2ef906a97385f5ac63f1ecf2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:49044a7f220759ee2393b22746524940a9d6d397467526e32ac0f9e2846ac694
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:598baf8ab1ab3e15b86d14c583e1db130e9973e15b7e9c717b32cbe803646cbe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:43a0937432b6d5d85d9b3032431d5a9222d7053576c8eb87d494aa0eb4eb0a8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:92008c57e88c802e118b3c16920d4cf26f64b08e390b953a543bdeeb9613edc0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:5f6bf8ca13c1d19d361e4173bb87e70ee7dd4e2a08910d4e188b8e8542f9e5c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:86180cead702e7659a4300384692eba8a25586d930a45f157b1b76c4476d0e9b