Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.19-debian-dev, 1.19-debian13-dev, 1.19-dev, 1.19.6-debian-dev, 1.19.6-debian13-dev, 1.19.6-dev

Index digest:

sha256:5975497edb00845846cf257141a2b7c820de624e6a8b41d10ed3c3f7c4adbd43

Manifest digest:

sha256:42f19cbef805d91b8e380cf064029a285af919154048ef2330c540fbb0b4d5a1

Size

106.23 MB

Last pushed

3 hours ago

Vulnerabilities

0
3
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:3bc6a363d956b7e1d262e75d1c19317f8bf2f18f0ce00050c6c1ec9d14fdd55f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:e6c0c3ab675bd4a1819cc17bbbb2fc916d683d647aaf39396611df747d9fa37a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:93636bed957e98f1288774e700de5b1232b728f622a485f2d89e604d7e0cbfcf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:e43a7208c1206fe4a9c61fa1d73331f78fd08f5a805eae027ab2caa16212ab01
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:9c0989d5622dedd69539243557e06c862e782aa267166d619d76b97b40477cbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:2e1dfaf59df90b3ac72ac64d795aa5034973d9e677b4cf6699e0afd534025774
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:8d2635fe2f38b1d7484b92c49278ff3a283342be13506c886077338d0f8c56be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:fb94715de277d497f7d9715168b6ff5973db6add5413c2bc2cd70cc241af0eeb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:66dc3bda36f2b4698d23ca2c09098e03c0f715a4903e91a094b2b13c35eccb40
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:15d9e38f01e11977ddc94dabe467a51cc33ff7b20d7ecf77e0d507d0676c4e49
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:80b0dfa6a1342a997f73c2061dd8987691299e8f675ab4755eef19eebc0f26a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:68855c9304fb47e3bb87fed9aca218503a62f1af856003a4442a30cc75540855
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:9580ba97d64a9d7e9ba4f3775e946bcb365711ccd5c340165b661d15a719e5b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:2ac1444ca2a06294cef5cce80ea09cb6948bcec5cbcb757d08d8578bc3f70c97
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:13920d79d7a335e63282a7c40cdfa133f939b54d2174ccff97a4c2f21af6242d