Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips, 1.19-debian13-fips, 1.19-fips, 1.19.6-debian-fips, 1.19.6-debian13-fips, 1.19.6-fips

Index digest:

sha256:b646d462b4d951922a84fe00ea74aa1811e5c451ad1e29882228dfb569abdd00

Manifest digest:

sha256:30bf87cd0406780e8b560cad81ccf097f6f7b25e41879c2fbd1d0c0d6d8bf67a

Size

90.45 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:ac48d633424e5ff0aee730072bea9c2e29017e8907ad11bb96c560854738b5f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:81984a075d4cb4357c124131df0da843420ec35d93ba2c14d7862d309a3924e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:01a0fec67295f11b8a570e7fbbb7796aabe4e75112ac72b49e7b9295cf7f3e54
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:ea4cdf9a333590de6abb6be13c64bfc1566a9f5277b9326f4cb431ae2358127d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:2f8c0e9755efb7356bb47ee4218138eb91d790766ed3564012aa9327f28b5920
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:4fca39fc58cbc6ab69587bafe02561c20288460aa796208f4ea65e2fdbb1ba6e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:ab4e6fd8ef26fd4e733cbc8108fd31ffe27486c1fec1ba8e00ba4ae833235444
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:0d8ac0580c2d25a3ce89d5a6d07fa78ece13de51e2fba9f85f24ed07c84d98de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:90e77462e732f50f20c81864978751a4769dbaf9c3433225edd4192d9b00cff2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:7a34cdf48eca69f638321a7fd020488c7b15a5ea4d92c7f01f0897318bf32f7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:78340e5d48d514bb6387167dbd91128f2d8f69629ef50235a1ec0f0821759ba0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:e068a7d70b705a73add5c2dabd15190d75f2b7b7023f4f413217daef2c361b74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:788ab6a3c6964a674166d5fcf8daf573a02528cc6c215b9d1ac19da12dd1c0e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:1ceb29c3945f830d0710be05629272afcb497523a7f420312d03c876f1001471
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:1040c42ace325775671bb4daa0d93300e36b450c9f030005ace3fdef54d6d273
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:12a7697eeec5e6c90e092d225be1e41b308d9917e5ccf9e730f23b1d97d13d0a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:2e461cdc767ba4e2b874b7fe713dbe7e214511145cae1ee4c480186168d46fc2