Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x

CIS
linux/amd64
alpine 3.24
Tags:

27-alpine, 27-alpine3.24, 27.3-alpine, 27.3-alpine3.24

Index digest:

sha256:d22c8cc469a9f96a5c8824e40e22a04ccfd988cc534465295021d3358ef0a4a4

Manifest digest:

sha256:ee36246000f96bbe31d4bc4179d5665819f32527e211cad789dd918058f3836b

Size

34.48 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:7d5b12db7ebc8ff2fb9ca22f92a9fcd8ffc5e20b99a8b4a204cc23f27bd8b299
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:2e8d5605187069c8b6e111670009c3b64d2dc0f5c9be31a6fad19a68f10b82f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:e3ced1638f6f9859b805114b548eddfac025ef48f0825ca14577c21f0beffce6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:295799e91a0d47306bd5277a4ed5378c3fe7c2383782f3ba38b1413db6f7ccfd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:2655c1e243ad69ae6e02a6e422e6b1b9d6e064de27bdb3b732f50d2d827eb5d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:72647069dbfce9b4210f6c0f6cf1bdd483858a92c717c93ba0870af74a0c40c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:a9190766fd7abaace766eb043d6678466d42cbe5117583999435cdbdbac18bb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:504fe2e2b0374eab8ffbe5cdf0ef7a10e35a422760165d4a8a0ca9449ab8e0f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:66e7eb0beae7cbcd604d6967515c7f473f7dbfd58c827fb9242dd706f9f3fddb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:73b2e9ca06827a60140afd5ce70c9573ec4c078ccca855e778d842f26ebcf680
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:a3ab1550959de33c4a6a0f8b3e3779ee1e53b3c954225def51c2d7f6129f9009
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:fed2d56394cf74cb453876755ad4e6177b00e29f183864f1379d64e934b26b13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:c844593e960334f7d0f06204793304d50fcadeabdf50409cb2c47073b98f1848
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:bf993d020a4aa940794eebad4fcf71c123fb326910073c47797ae10ecad84a96