Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

27-debian-fips-dev, 27-debian13-fips-dev, 27-fips-dev, 27.3-debian-fips-dev, 27.3-debian13-fips-dev, 27.3-fips-dev

Index digest:

sha256:e0bfeecce1cbf4f9d6c5f196c71960b1fc9d409953bff2610729f72077c5b8f6

Manifest digest:

sha256:7336124ad6671a89dc36d48d96578c06b1502309aaeb49e3146d97b422fecc3d

Size

82.66 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:dd5eda4bb86207399b2d42dc761835e6cf812517c118b94bf7d027df14d07b88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:56c26694f912ac0b8359cadc8e18e566437a83c5b88eea76a677afa2d3744d44
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:23df280b673b09e42460f9c56511c85549562e9876c169a3d1d18a392d6283cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:7c7dd8442788ad2ab600c6873935901343a847109e25bf60bdcb209a5c2f5f32
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:5a3f7a57d4d6efc6530d458fb33a73ea6a163c204998807f1f24ed5fd37fe87e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:bf3a0bceab9b29758356eee35fc2bc21a7268e94351ed174934c6554a81d1666
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:e23f23ec5925b5c529a98f043f3d8617ff9e522677069512e346c700499765cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:1b30ba7ecc8d842e2a0783eab4f1682a7f59ea0c955c37a38ef8f4ecd994d57a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:be20ae0f97ecced0a055f1097f6cacc57e66f9c47d983a5aaf53d49f63e15622
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:d243bd2bf336468acf463f86f64c1664e8202ebcd8c0d6270580e5e011c84513
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:5d9d21849d1ca7e06ad0b0ec6f93b42353ecdf22ab0cc813f70524ccefbb67e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:39c9d5a36c0625f3b2251a5eaf2af244aecf4c614a59e91ba27cad69a7dfa61e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:e549cc69c7d6c5b0ba0f318ee297369b3d71996729e550d99d9653892389154b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:1fdd1b87a700a594bada96667d26529e5b5af87a2f864330c7d30609d4744708
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:755106c95c510dce2f96901aaad4054631733be9fd7cb5b617bdf364ee9bec63
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:685be16b216215f23532492a19af14316f53e2bb14105c7a7c328789ca4a5137
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:4b2a833d3f8ea9a444ef676b44df63f34613c07547dfcbe09387741df4e40047