Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (dev)

CIS
linux/amd64
debian 13
Tags:

27-debian-dev, 27-debian13-dev, 27-dev, 27.3-debian-dev, 27.3-debian13-dev, 27.3-dev

Index digest:

sha256:0ab7fa5b87c4121d09d3d8be9fa096f69f406c7364626c061677692e6584049c

Manifest digest:

sha256:416f9a4bf3b7147202dbf6ce3ac3f6b3937dd3a626e298c6f6856d34724798a6

Size

81.91 MB

Last pushed

2 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:41ad266bbfea69a976ebfef2e322d4ecdd31bca0cf7c26169905eef67e60d4c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:74c28a162e529773c0b61eef782175881452d6129d30387eae5d6fbe04c0335d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:3c059103eaf80eee785464e7422ad7e65e9820f68f21d14dccffd171d0780676
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:7c203ed35a4dae1707094343cfb5e6a4e5fa7bff07c0491c6ca61b66386b6e80
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:7b4bbaff562b21bb4090f9c40c7bffb61a9c6c6e4eefe0129f3f5c0ad9c1acbd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:437d08c11977765886410a5c03782a8589e2d7bc2a91d3a602052de99f28c514
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:5806cd60108abb15a1cbd4e078e620b1a4191f9de945794b5a91c3f8e50ffaed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:0e397d6726d88fb4236dc5dec8cffe7f21db3d564f18d00e0ee989e60a857f8e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:5fe2f276d4cff69b4f3784a0ec043aee9365ddb5486bd792df25d32b3c234c05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:f6aba381bb23ba8bf78573d8aab582e983ec591299e7f2e9ac8319ca58ec6188
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:397e3afe2572902f3fb2f04dc48365e4745ae48f8907efbec8c203e636e72222
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:36bee25a3a4462fe7f145874497c5d8308d546f80b3139027a47efc96d23db97
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:e5770ff67e73cda1278c92c417a9cd49c9c2d84ccd4e827c99f556ff5eb373f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:37927be2b84b0a088521f9ccc5e1db76626f007338e76718bf476c2538f946ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:d8caf51df74493944d84c26d61cbf3adb0d9efb5d30f5ab5d47d26803f3e0e0f