Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
alpine 3.24
Tags:

1.19-alpine, 1.19-alpine3.24, 1.19.6-alpine, 1.19.6-alpine3.24

Index digest:

sha256:7be8d27c58cd5cd4dd52a45c3602d7591211b6a8faaafeaa1bf9ef8f6c9ad093

Manifest digest:

sha256:41b4eb2ab20e16304f42bd5c56ef2fa4e170b7adcd28ee3f81249e847d63cc20

Size

43.48 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:566bb5c75b4253d2a6a8dd9ba7d99b51c91d0c06228f00e5da65294a932ec6bb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:94221d5bbca8e159674a3b94435d5ee34ce564ef5b7bea0c747f5cf09ca3b24c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:385569dbe047cb62b862d64594228ad1ce1f8287d5c7d0cc525a10f1d8a369d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:c8895cd6db94b9c8a846c4f95a6fad47094798408a2148b7136729bad1f8ee2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:e26470e02d4a0d67cd251d0b44e97c13ce261bd288fa0c6a2227de2bab8ab74c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:d90d3c1588ba12a7290bee2e045ce8a4899f737b25971df7bd6ab678928ab6d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:1c6cdaa9edf18ab0fffd1ef2cc804b50f0c344bd11968ba4addd0967506ee40c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:cfc8359bc4dce156cd73957a4dbe1ae58b40f5d6810fb44ba14b33c13ceceafe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:1063d53f1178b50995b68f942969f68c59661e4de2a4abd80fa09dd2e427cce4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:5390db3d2006d02ca3dbcd5890564cd19e2049e597706ab229cdd7b2217d561c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:772d873fb4c471c2d37572718989a4eba36835ab8a4f37c053f6d6f3964a1733
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:508f3989b2183ad5e56179ff5dc84cbc0b7195b647b66d38465595a377d5398d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:4befcd0cf5d90ef0954209bf53edd833edf5579c502bff1a94c03e14d8dd7f41
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:aed8f64d6235aed6f4127c814609c21b8bb86286e590394564f07265b0e00807