Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

27-alpine-dev, 27-alpine3.24-dev, 27.3-alpine-dev, 27.3-alpine3.24-dev

Index digest:

sha256:1c0099dc103fe8580cc36434ea0fe24f2a39a1d8919ade7fe1188c6da6069693

Manifest digest:

sha256:f871c1b4940a51c53ea3c09a9bf595987f909ef00a9f060fb72cd84e08b48b33

Size

38.06 MB

Last pushed

14 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:3a75d2b147c44823d566e962bced5bb823908afe2b8fd36453f7c1818769f496
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:684aba30bed9a960b7cf3388d7550a804acea79fde9ed54c546f8bda4e29b49e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:7db710f192ee6ec26a61c2c1cf48b5894734dee491b3027c0facf2b04ead8f2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:b212532a4636149cb87cacd57419d268dc4fa9a98531182a438267ff9855e1ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:7c31cb4400c74fbe47f4adb0bd84a1ab855cc4dee050ed355d2663520ba0c3eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:80b4214f4363d44a352504799114cde0ca1d28024530586490470133ba0bc7af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:36de2e2b394dc49b23a48b94fbd0b249392794b14264c1b2af85aa8ef51bf3d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:9e6cce3e790573783e0899a3b82f625173e3a5091a7109bc4f5cb422af0c9cb8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:63e512f5c9ee7858c33487fef8738bc4331cbbf6ae2868d99670951e2720e09d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:ae02800ef6336f3dd3a30e1bc98198bc3eb72a33514adf35efa75fa55c7697a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:5d5549e63b070cd63f26e6b4172794df1243cc0a723cc5147043f460db947aa2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:14c50e0f1171088bba6bd49829afba82e80d2fa6c18dbeb6403e6f801c1bdfd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:3931a9c2181e5464217d7253acfaf2aef53604d1291eb29627169e0d98266446
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:ee1399113f7c8bf615e90c2a7c7ba2a0ae515033fba6898ce6561b305b15f778