Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.6-debian-fips-dev, 1.19.6-debian13-fips-dev, 1.19.6-fips-dev

Index digest:

sha256:9f555576d6a1b9121f52bb2c3e44976ceb70cbdc61483e4a529f17ca0333acc4

Manifest digest:

sha256:a5f2d2a270475565ac3bde30b2bbb16504917e28ba0bc3802b2e6342a7d2a46c

Size

107.80 MB

Last pushed

14 hours ago

Vulnerabilities

0
4
4
20
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:a590c08731a18cbd5f67c94aa826557172c457591ff1614f542f720fb44f9a57
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:2e785c6b6f67a135307dae65c11aff84e41bfce41312dd845e4f60ab8e8fea30
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:79859ca08a61c002d41426060f6229bd8cc4b6fefade99bc727664c8a96f26ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:f969d829a1a1769124dc35c8e9c99281cd17ec7a82d9d96996e3d6ce387debfc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:55718b0b2c8d930291e3bb563e6fd2d7ef349892c3ddad8adbb5c3fd847a9252
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:21579200acb504936c6ac2697209eec7d86c770377838b6e9b262b588d9d73d6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:408a9ad371f928acef62b18003de4033dd2ba5fe16b61820c4da543093c07694
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:7eaf29263ec918b65eae43a6ee88ac0c9b1a5c93a016f857cc37e7599d4000d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:1bffde78fcff91d70a9272405f56ca2c9a951215d3f82683abd1d8549435169d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:64921ed643f18d801bc41fb2f82d59484d638644880455883ed42d3b06cb339b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:837cdf3601e3c5fe52df0f6c1c9ed58643520b9719c0ed92dde3930889749e8f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:05c721671d21432c711040786075b1d3366132fe4f12f924f33f7ad37217c12d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:d797d579d939b78004bfd3e6bc25b9c204682da2df82b0530c04c4e54046dae9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:ce42a76350fa1feaf699e41655f36d9a5563af67a981e8ac17453c4db06cc13d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:263a8f99b3e9378ef5129ea1fcc53fae6cdcc48c8ca14caa99b96f63c6c354d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:07d956cb9c1ab6a1329909e026c0d6048562e28734dcfd7744b617a02d46815d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:29ddb23f851d1d38d48d29a084744caaf86fdc1efd5c282ffa5cd471d5d280ab