Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
debian 13
Tags:

1.19, 1.19-debian, 1.19-debian13, 1.19.6, 1.19.6-debian, 1.19.6-debian13

Index digest:

sha256:a47c19f92019ca5072bb836465733bcef57db1ded6ef87838f421bca0894961b

Manifest digest:

sha256:53b84cde5fbb0302fc61dd26d2904dc26cdcf9d5fd26c524d88c9b008e801f12

Size

93.47 MB

Last pushed

5 hours ago

Vulnerabilities

0
3
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:e1ee38c7218699c95e793eb9701435c06e9448d34741705ad79c5ab87143fd37
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:b82235a63e493c6f6f3132728a6fcdb6dd0f2dc9c0d47250aef854d6bde8485e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:4019d42be0a09a2774a80a19433d0c77dbcb2c45a03fa2471d08bcc60c96a224
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:9734fcc033f8d77b2fe2d57b2918aa7ddab1baa45cd036d2d3baaaf5c833e091
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:22644e6f28c3ec19a86ccc97d06caa76afc261f2d5165da17ffae6969e74e70f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:f30cfbb7b23092201c7195e115d68bb46a2917d15508d1a30f3568d149439b8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:d8cc4f23d105852bbf94789f8b77deb6821e69e5375411826a5e58a5fd88d966
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:74378f6f8924e5165e259c8e1e84daf245d8d68db7456279978a7548fbd509a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:8dfde5547ac8a9649fe244a2f77d91a406bd78724c31fbc83d6928fd47ef003f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:83ee2c2cef6cdab297217fb413d11c9f35ef51788c48f38d26524f16de25e4e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:6d2d600164e7aff1b6df4121b4a3e29d9b7045e0b89c8d61653c3bd3775f4b03
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:61e4a10383159047a4f97b2b00b75aa39f3e123a6cb2e23c829994f865603273
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:eb3fd208fe9f1e78ae3128bfa1540e561435530de6cd384ce69a84c634f2d05a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:59506e812de48b55e5e04d0e4c9cf555c5fd94ab301b00829f5ee9df2ec3fb01
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:d7e35a02b91f9c8a5fd4b571b66d560f9c822017bcff59cd44dcb89828f96d85