Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.6-debian-fips-dev, 1.19.6-debian13-fips-dev, 1.19.6-fips-dev

Index digest:

sha256:08e78eb4a7fcd5abbdedfa10d7c370c3a4f46fcb6d27e582505fbb5b338bd85d

Manifest digest:

sha256:51d886989c0696ddc42f69751fb9dfb41f6a9554e4173903be6695a6071dc62f

Size

107.80 MB

Last pushed

7 hours ago

Vulnerabilities

0
3
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:0a0f78c705eb6a009673c66546286e487825015fa5157084c9ca27264e6c2e0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:2e7f9dc4d5187fc1d13e57493539527d5e739416a78a5d68fe249312268639c0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:81eb4c1301345fd60ce13d77dcb8a7e14cdee18f677159dab44962e898eb8fa4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:9d4478aefdffa5cb4bd0a826254e4c825b22a1fb64d34db8fadcd5e83499e397
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:e40ca38d58ac9876b885fe83ffb4726a0f96bdd63c0ea314d9b4bd21b54eeb38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:d439ab463086b97b18d0f1096a3013ea92a345179456bd230b132f5e6c7631fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:4185b8a0a2189e6506fb8e25d6325f14854e8a573385d2592b043ff7d13bad44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:b59b8d7293c1a113b16cb46614bda8e278ef7aaafe210c1be5137fb96a6ba9fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:2bd5bd1d161ce0a74747b9900c1acdafc9aa936796e4ee2460461e2e9e09cb51
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:105bbe6dc63a1aae997c2e9fba65c705e9e794ab49c3a883458b2f0ed3ffb231
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:bad567b8c7eefc057d09ccba0066a28a2d299daaf19e408d589b6a88844d6f77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:454c13a3814975deb2b5e4dc8016367236c6d1e78968a9d73f320fc1b452f902
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:07f94dfcabeb9be8c74837d0d01a9bd3430d5388c612d99a8c8c00370154bb65
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:c7099b0918dd9a8308b3d65f1d2b9c348a67e325a98b00f47711d3420e61d78b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:7ebaceedf9278822033eaa15ad754eebbd0f5fd60837270596f29c01264d09bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:3ebc9da4d1b6ca4018c9e75b7a0873b723d3fc06c0f2480a69e5d97e7d10113e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:7eed8d257719a3d037fc7aac998730e5bc3daf35e18c366f63dbf0aa2fc49ee7