dhi.io/elixir
1-alpine-fips, 1-alpine3.24-fips, 1.20-alpine-fips, 1.20-alpine3.24-fips, 1.20.4-alpine-fips, 1.20.4-alpine3.24-fips
sha256:eff4c65020e769640abf82120e8d5531d655d65587690e6c7fd1ec0a3e370bf6
Manifest digest:sha256:b196111093219547972970bd12d9871ad1284f75d258b56acf139727aa720228
Size
45.27 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/elixir:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/elixir:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/elixir@sha256:cbee29ef3dfb0839f291b4f18b6010198a8fdd09f32ddc37f4d8ee385b2b5328 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/elixir@sha256:1ea7a6aaef65a81b1559dc7c42b0740ec35d3e769370f4d55a4107b7e5cdfa0f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/elixir@sha256:bf30cdfd8e32e95f6f79acd045db3c2da819280c79a05ad5287d1a4a0f4c3afe |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/elixir@sha256:9160ece4aec4bb5b0cd6197545225badf3cc56950f134a2534168e380ce45e6f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/elixir@sha256:06b22a8cd9c19a6dc051281ad45134e0098f1ed70af18b431e0a0a901653ec77 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/elixir@sha256:bd2ddf5fcae3ee50798db9ade8ec6bd64ee5c7aa77a067f0e4431fa32e7be504 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/elixir@sha256:7c1148f1e81eb7e2184712e1750d8b9c1c72f12c0501d31ad610a700dfc40297 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/elixir@sha256:5f45ae9f31561daae074e33dec87715b903b6d1aee63cb4daed96e29bc6c5d9e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/elixir@sha256:c96a0599b5c838c041e7bdbf32878218bf26b72dc7f8dedef7fc426574824915 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/elixir@sha256:4215cb64f00f59a52571d4f55a2bbe73938b3efffbd2c424a99014e77dc1f101 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/elixir@sha256:7937c54f594876bcd88600922a34e79319ee806ca4b13741e7b113eadde871d0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/elixir@sha256:cc0435b3f2c96bf7e0ab8c181a30ad957bcd83fe47f7b367e88cff97bcad9d8f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/elixir@sha256:ad4740fa5b8773de266b8ba7b6136e58691c873518bcd1cd5d4222710be19d5c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/elixir@sha256:a819068d0054c7d1095d5745196e334ac0acb82386d2823db4e2b21ec9806518 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/elixir@sha256:38be80c698aee192cc308a7ec03ca144fea40cdf2afbad4fec7da39642f335c3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/elixir@sha256:539accf6c43cdf894a7acfb282cb3a9a3789ed3ec234aa9e22679457997edb56 |