Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
debian 13
Tags:

1.19, 1.19-debian, 1.19-debian13, 1.19.6, 1.19.6-debian, 1.19.6-debian13

Index digest:

sha256:6e685953312d511fb98adaa70eddce99bb5b787ce894f807327b759ae7b4b48a

Manifest digest:

sha256:b63a76bc5be72ef93260ff48e84229cdf4b9b0f5cfc0923edd9303203899146d

Size

93.47 MB

Last pushed

2 hours ago

Vulnerabilities

0
3
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:1fd3c88a9ec5d1156abf64d5df76ebd6acc91fdc2c7642cc1fbc9fafab53710b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:f02996fc9f71fbebbd198ab0d1e1f533c376f337dc5ee88cd90c937d35998fa5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:ad6399dc7f6d68e52c775ef819bafd001256a6ab89bba7764bf75d4c381ad708
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:f1491656e18226992ed6ef073721007f5b3b999171dd5cb747964b8c2282921b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:2cb3db820b23387821fa3398a4153cf7fbc4f1a5f20446aef0520dc4dd945fd5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:7fa51f5480c872f9512299d55108ebcd383f6129c0699173bf9bebd298f67c49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:1b7612c953bb0b41f2208d6adf86e5e49d14fd1d9c22ac63402630b6d94672b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:688b8954928be852d5f4a96f11b0df8b4eee829f42505f8fbe4e94203463f1d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:6ce35e6e4424b9b017ca6055d833309719d31baa84a71fd3f6a52ff04d5523b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:a64c862693c91b8d1657df94ac3f658a9562a139071dd887534d26bed53ccb09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:4825213d6e619f839352074ca31b4d72d08265519e8030fee8e26321d0408ddf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:0314e26979afded7808c1ca81ee8aae73a39d6a9ae24675251ec65d8d51dfe92
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:a9641be6c7499db5bbab8d241da2d39fdd3e2194b67666b0eaf394eb146097b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:c5fe3f207006f9d1c436817278fd831cc1500c8e5215fcd4dbbfcd39f86876a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:84cc9f314098e6f5d761458ec38244af3a747ffa03917b3b9a2d8432c9620a5e