Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.20-alpine-fips, 1.20-alpine3.24-fips, 1.20.4-alpine-fips, 1.20.4-alpine3.24-fips

Index digest:

sha256:eff4c65020e769640abf82120e8d5531d655d65587690e6c7fd1ec0a3e370bf6

Manifest digest:

sha256:b196111093219547972970bd12d9871ad1284f75d258b56acf139727aa720228

Size

45.27 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:cbee29ef3dfb0839f291b4f18b6010198a8fdd09f32ddc37f4d8ee385b2b5328
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:1ea7a6aaef65a81b1559dc7c42b0740ec35d3e769370f4d55a4107b7e5cdfa0f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:bf30cdfd8e32e95f6f79acd045db3c2da819280c79a05ad5287d1a4a0f4c3afe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:9160ece4aec4bb5b0cd6197545225badf3cc56950f134a2534168e380ce45e6f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:06b22a8cd9c19a6dc051281ad45134e0098f1ed70af18b431e0a0a901653ec77
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:bd2ddf5fcae3ee50798db9ade8ec6bd64ee5c7aa77a067f0e4431fa32e7be504
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:7c1148f1e81eb7e2184712e1750d8b9c1c72f12c0501d31ad610a700dfc40297
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:5f45ae9f31561daae074e33dec87715b903b6d1aee63cb4daed96e29bc6c5d9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:c96a0599b5c838c041e7bdbf32878218bf26b72dc7f8dedef7fc426574824915
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:4215cb64f00f59a52571d4f55a2bbe73938b3efffbd2c424a99014e77dc1f101
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:7937c54f594876bcd88600922a34e79319ee806ca4b13741e7b113eadde871d0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:cc0435b3f2c96bf7e0ab8c181a30ad957bcd83fe47f7b367e88cff97bcad9d8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:ad4740fa5b8773de266b8ba7b6136e58691c873518bcd1cd5d4222710be19d5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:a819068d0054c7d1095d5745196e334ac0acb82386d2823db4e2b21ec9806518
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:38be80c698aee192cc308a7ec03ca144fea40cdf2afbad4fec7da39642f335c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:539accf6c43cdf894a7acfb282cb3a9a3789ed3ec234aa9e22679457997edb56