Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1.19-alpine-dev, 1.19-alpine3.24-dev, 1.19.6-alpine-dev, 1.19.6-alpine3.24-dev

Index digest:

sha256:61174f784852e1036803335634b4ffaabcb1fd24e67d02ccc51479ca59d0177e

Manifest digest:

sha256:90992e552bdf75be022c42c7bbfb08bf2d9e3ed75d99dc0855452fa725698d4a

Size

44.64 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:b0d73c6d958f54fe550c2c17e7c623307b0f9c295c099e464db731452edd8fc4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:f166e46a253952aecb8e6c134f9564aff55f6aee2f7a608c0a9854763f391066
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:3560b6befb5efb9b1be791b79ca52625e45c1f2b9053de6c9eb3cfbcc17b947e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:3a9f8bfe3016793ff048614961c187bfc6c54d5a3d83733f6f75d9472b53f189
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:3f7da4c898ac1e6bc59430b4bb8cc36a737d9b0c24ea122ef3f7474dd5b7f3d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:a29825afd24404503777084316e61ef39a997131b29ca5d10487126276c5038a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:f53fbff7a473a05d969f05a4a309ff7162f1eb407a1bd49f77edb2607142bce6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:fb6b8c5142fd810956dfe7882443472fe3c2c66c332809174f48dbaacbb6b82b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:1678db55ddb816c41e17b057dbd33426b3f301c7984a075ccbbc77bdfe6a64e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:a68c6c50e0868923904db6e3e9fb23d331a1cb9dcfb7da692e1c46902083ef10
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:ee357be8ba67a2d52efb0977d4f385ba60320b8e6b093cb07009a22ad9291cfd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:b77ec4fccbc61edce2a1d54f1fb0bfb7e4261d9a6f8e61e5976083869b581673
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:88def2712a92d1a0225c9c3fe83e2c29ea5f70b4935f31f87eaa35cc79c08b2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:afd5bd3eeb80b683e0e742c3901a7898af4bca0f9edd428269d060ea71e614c6