Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.19-alpine-fips, 1.19-alpine3.24-fips, 1.19.6-alpine-fips, 1.19.6-alpine3.24-fips

Index digest:

sha256:bc353c631c2977e15dfcf6c79aadbc840b087955dc4036a80e6193d3116e8b8a

Manifest digest:

sha256:3d3d4460b1c37b7ff8b4a1e2df446382795695f9c7f26752ff65721fa45f5ea4

Size

44.97 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:782200ea728eb3bcf638fce4418e062214fa79a13562d5f294447781953ecf06
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:80f68f399d53abb0145c3352e6908d41630bcc6a8353ae092e187a4aa041fda1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:99b03f5f34edc492378da09c779e90c0576758235b80339c255cf696eb8ef0a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:1f8593837fa3b4a9c0ae47dce9a20d7ff71bff67bdd029315b62ec489e892f17
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:bc61200955bc5237844a82422aca119faff702e1a0c9e9f6c76ed18c032edfc0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:f57ddc7e70b9849a5fc372dd6a05f259a91d0954757b69c7238a6531f807adae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:6ed7371d304934bffbdfeabdd36db3a06d650a03248b41c7c8bca2bf7056f790
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:9065a723c63a0578923697e6cd4768f36af4bd159ad211bcc2d9976a7a5380cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:6abaf46e973ba071322eca6c423ee799413f630a449e048490e6e93786f6628d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:51e9de765cb5caa606efac1cebaed94fa4a3e00dcf952b294d875a15dfe06f38
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:af78c190881b98888abdad13b3c01303366f82b012ab662379346957d019ce38
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:aab1b139ea759bab20059d939028308244c57428ee63c2f18e5c88417c441d44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:c9fb71ebf2b116b00a3d442ada8703d7509417df6bf76ad40ae0676dc5b878ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:7572365fe53988da83793f6e3f8504f0ff2b2a5731ad5ff78ebab9c00bd444a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:eb2d3ef2efe5aca1241a22ffffac4218a76db2e3262541a0f88ca27db10dabe4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:e50a05edb40ec23ff16d6f1ded9b8dd2be736415a6634c29f7f6a363977d0af2