Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (dev)

CIS
linux/amd64
debian 13
Tags:

27-debian-dev, 27-debian13-dev, 27-dev, 27.3-debian-dev, 27.3-debian13-dev, 27.3-dev

Index digest:

sha256:c302fce37db1bb6700459b44b5184101b22aa1252acae3ed68343fe2263d0398

Manifest digest:

sha256:980458d12f6a03617dddd6f90e8f89a3ad319bfe25e3f86f3193b29045698e76

Size

81.88 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:37ef85744104321ea52dc76df3d6cde832cd9636a662636ba347437f72015b5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:43eaf53ddce4c0b767540aba935c37e051754255b60de6436404e5bc94b6a45c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:fff40ddb8e907ed2bedbe37322c25e3c438596a2c0ba62ebbd32b1c785dc6620
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:ab8e964e604bafe002941fa5c327affe95136af5084f823c2338dbaf763f59c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:bc0e00b8f17dffa3e55014a4a1e1ebdb62c97c44939947c5717398af3835ac03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:7b8feabb87f22e29a414d9ca870b0198f07275e45308c18dcc14b984a4550165
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:8ab557d560a34ee314998b5b71d48d070637fe6dc080f2a137a1c48d83be3624
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:6bcfb6f5099b249c76c17fb0be441a04be7f2b9b9e6d1c17d2f1118321831909
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:a2f0ebca51dc2cd31ca889825c6cf388a1f792bf56d8837692b79a808f0de8d7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:772a831bf0f644163fdf573bef121a291883f43342139cc8d0dd1698f0fd1b97
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:92397131c55934521474162d5ddd85efb4a7c118f1c388597a53b59a231c4f30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:8df11a5c39deb9119b3efd9aa867833326507173a7b5c2d7c643db9f73fce447
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:a17036e8768b3a2508cec176e3d9aea021a0755da02a1f459a1fd773bf694cd8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:369e11dded97997dcbab3d922d95c169d8b12f839336e88248a18ae05078640c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:224138941ad39bd47fe7bb9509421f3b3ec7ad2789542e0fc4f837df0b8afb83