Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.4-debian-dev, 1.20.4-debian13-dev, 1.20.4-dev

Index digest:

sha256:e81ec0434d6f1eefb98c47007426de08bc47d52a450db51f488bacb1f020392f

Manifest digest:

sha256:3d2ab9c9b5591f19c8f63253b2967be988bbb042fe6c1b7fb7a1fb182caeeeb6

Size

106.49 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:048e2411b60c587aeac26ed2ddc904cada93cd911e5c8666cd475aa554b98b3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:5a87c3bf18ee411a0ca343be46f0eac6c42e82d7ae9023dbe221db8be7df076e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:1e708df9e913f5ec9350d10710fb1a5cf2bc2df9d9cb7d6b09e51b5b196804ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:30dccf3c6cf5a2b8a62018e9a29083d98a2a6aa44bdb933c619e41819b50a47c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:bd1ea9c876bcbe37f432c4041b1e9a030500bbf03ff6b8a3ddb56ae06cf163ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:aea1c1d201ceb95042ffeca5ca45d5bef17adced85816ba4a3451f9fbb8f9977
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:0442c94c10546b19425ec3b17952f0954cf4cec96bd80bf33e86af4fe0482508
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:271f001fd956efb9168f15f60363f358f0cb738d09a0548ee34526bfb5b235a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:029a2d6f9b4a27fdaab4b677c9eb9c3d71980137839f0652fc8faa0cadf9d710
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:36dfb77b85e8a7377a8b4fbd48f02c1f8746663ed8ca7c19b1118131d8a7d740
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:136836c0b427a16cf5b129254cdacddd368ebf2a1840e511910764254b287edf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:e4dbccdc271710cb983fe854ec4a96e80c7bc9264cca82507b2dea49fe1f7e8c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:e7d7c352c65cb5af3dc6117e908636e58d256515a7c5f91e94300be4d80c9300
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:ee74df5d6d61e6dbe261a36cf3a8b2e8b1c5fd055408893eec6c616de6b21cf2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:8be573fabf7d733813160910592c55ff3cc175766044bc488dc048645f485133