Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
debian 13
Tags:

1.19, 1.19-debian, 1.19-debian13, 1.19.6, 1.19.6-debian, 1.19.6-debian13

Index digest:

sha256:d36869c4ef55d3df1dbaeea0f93c05ca09b6c8e0a4f04aa9d098be5121d59671

Manifest digest:

sha256:7c2d9e78be154ae8a7979fb65b92f9d0b258d8032116498678b6c1705afd6836

Size

93.45 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:79742e12491e030b20764e421986a5260a29f3ab40d4bcb89a91fe818849fc23
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:c87fde8eecc00b8c8c0f9d1f866326bf07c04e276df161b7f1608e7e1b2ad523
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:24e4d4afbdaab23295f82dd26ab27ae812ce13fccc02e33ae434d13cb7af21a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:fb604c56ab54828af395e74f05f5b94c0c24fb175693f8e08d6d0b0e6930195b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:3cbcecdf8750e6025289df102415dc0ae195e3f812922f5320158c88e5976086
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:ef53df4ec2087a5b241f1bc72f0fb65ffb688a65d878b8e5c90a25f6b6a04b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:bb1997e988f348569844946d43a16aa48195392bde64c99e7fad04ebb7f1fd12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:1332fd9a2867df83a9cd8e4a94290447784215393f0711412e5a7e87fe0ed039
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:f320c440bee6bb79003404d3d770ed3778463d3fa379c253a28fd7b3e886d337
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:58448a1968c54dc3068d08aebf8d499db4fc87f890ce93ddd269fc643fddc0db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:890536ede0d0f13a448c9d9757fcb8d8a330c130b790425db992fde128688b62
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:993e6c78be3b5ffadbc6d774d1f0bd67b2e952877abbdb47e506e47d8ccbf4e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:af5f1308387dfb4a76843929dcbe25b0be61c660b15e534081b9fdda307dcd04
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:0071dce98fa3c8668428a614d7a319a1b722a51a9c06150966a503322e53978a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:0145878718cd8e898408978494c698b91e0643723e8e2eec168d3777377f2d15