Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.20-alpine-fips, 1.20-alpine3.24-fips, 1.20.4-alpine-fips, 1.20.4-alpine3.24-fips

Index digest:

sha256:63591f5676fb22f484bb6b7d164051ad4b5d63c8cb87a7dca339cb7d4ac2c0d1

Manifest digest:

sha256:7e0b1ff048dc36bf85996f5a2a2c1649e3f3e98c36c2e26de84b2cebe975fbed

Size

45.27 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:9bdb86244b66f901dfff6f8ec024c1b0eb3614ec63e6f9202df82b920d1d0214
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:4e0340d80e93df95a2146fa6e5af0fccc304338aff5dca938d5aef16f4f1f255
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:7b418fe54330b2030875ea035f6570b74c48d4a8fcc7d5266f4a142b6ce5a90a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:6b471954864fd2b714a0939ebdb02942542b497b8b9509e30d7dba363cb15768
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:1789ba265d6a974947c62d1e1c1a8a04008cfd81d4f8a0e9b4420e8d36249ef5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:ea1cd065d96da2a24efb8f0cdd9e9d82a3fc4017c55f11732cb44c797653cbe9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:926f97295b13d484b40474260cb8416179eaa18debe6d48ce20ab887b799a3f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:ead9ce972a01230fa8a2d25780cbddf35e8301349e3091c3ee23569df1e2c9ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:ae7d6136f3529dabf415f3f460d39bb7a7f16a4eea7f70ca5d1f089a41861360
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:59abdb46f771d7c4ea0463224c147fec406619a8bb171f6d3224f8f7a1d45364
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:3520dfc0bc5bd70c8c08dfb7fafcc71dcf6d3c90a425fe50f32603ac98ad5390
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:eec181be4d9e533b7155153325ca2bad7fb88c5383750e10a4aa3fb18d5f9643
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:a19431e43ff88774c31d7ffce8d9484f751db3f1d4ffed2c33fde530e63db896
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:e371b02a5dbb3439ff3afa0828dfbd4a376e3bf7333b74fe0d0d555c21365f24
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:1970a39fb04efa9fd15fa2537eab229e88fbf1b428acda3423d8d2e47d2d10de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:03a2e043345bc35b0d0ced936ccaf0e0b45b26624ffe6aa045fd106dee4fdc3d