Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

28-alpine-fips-dev, 28-alpine3.24-fips-dev, 28.5-alpine-fips-dev, 28.5-alpine3.24-fips-dev

Index digest:

sha256:b9b8d3b1ab3c84ddee3e530f8bf76204159a14e8373b36a5a3f1bc0c5c1e4525

Manifest digest:

sha256:5d253dd4cf83c4ba1c8aaa59c0347a765b70816c90bb562793b45b7c133733ac

Size

41.26 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:0714e96a83a52791263ff324220c716b67fd1eddc293df84235b583a76375f5f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:71fecdda5190960b84eea2d42bf19cd5706a77d85dbe4cc0f3e2c40fb3c50c49
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:773d9052eddc7d1d5acf81651aec881d245ab150af832bc462f45702c3eff9c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:0654ea9cc915e5f39d0a4b07a400b5f1776f092da4d8f9bf68eed6ffa459b9ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:e47f7d844d6aebd08bbb830be3afede79a2ea8cceea3c8b8011705c3a549e5a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:234c4b6b83fcbe91ec5a6cf0f1b7488c573a413758f1b5634444046f8e443815
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:978ffdb29a53f176188e1fd004e0048dee09a8a67f2e6523c8f64eeed7e65f12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:3207e752a12c30e6583c5d789441fda1a11d25e18a3882ed9e95ef3b13262d12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:3f2e77c4f4f080c164ff8f2378aaeaf8d68b589c53c0d68e384e0c749f2f65a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:0067ac3af77036c5a3e0c25600f609cc492b73532aa591b7a0e196c9a905518f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:132abf29156422ef72ee39a1089a30f0c1972d8a9a640ed9106e3a2c9aa43130
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:31575b6f57fd5c04625a73914716324c5008dfd36bedf4c728d92e55de813bb8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:c23f07dc4e6732a60a135751df740226a9fd6746499a9a70ae469f9fe2cea57f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:eac7de49d47e2754b79d5f2150c8f94791a514aac066b6c14f35fff6814a103a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:1f92b957c36f1b51c95b9639fb75d61ccd56aba3891fa193643f6091ce6a182c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:4d3459f7f366d5b2b5cd561233d0ae7c73698357563cdd8d774aea16ab9ad624