Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.4-debian-fips-dev, 1.20.4-debian13-fips-dev, 1.20.4-fips-dev

Index digest:

sha256:bb90b9822072b9de716f6f2e831d1198d3741d34bab4bab05e815b42f295a4f9

Manifest digest:

sha256:5f39d2e48189b42592774bd29760b22a1847bbcf1d20eb0688247f9729ff1887

Size

108.07 MB

Last pushed

7 hours ago

Vulnerabilities

0
2
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:94f904cb0cd97b18498aaebe9411130431573f2d524a2956f9891675e6755a5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:4df6c6e509e16407e2388021d2a2587040383885c18e93e69457c34355bcb3d3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:7dd098fe79b5f2ee41dee7c7fd4438f203fac03e7b45ab389b55bca10f6aad27
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:cb5116105a020704d3a609f5d1fb31bf9c37921724d62422df2f5e2cdd2b3263
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:21895e6c42f417ba287107442fd33f5443c75eb9c70fa33c3f3c9de404214bf6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:fd03a7ef41c700275b6954456ec5b98b74f7778e6817362d9f8a50d4fd2dea4f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:643a7a414ce9b58124cae15eac8aed8616ff60a3640e28fd59d58b2b0ee2f031
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:d319d3617e8e1cce135090cf2c88812ec80a92bbc94fc35d3bcf1cff7790f187
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:36f0fb414f9d5431e818ea8e0faf3d4ed581ea4b7a0d4ce5e4b373213f02f008
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:5aac7db471609f5a8069dbbac12ee85331f0355e635c5321adc93be76d2b2fb8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:065b5074a45c007577f40b3446657535935472c41d2825b620b6607cbff22016
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:74bcadbf1564f64a78dc39e2ef321ccc4761c1716cb7524cb494c401785048bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:709ed62c843a1a6962eb77b0ef077f74c9a13abdbf7e766937398f7972cdf6f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:a17efec37ea8e5fe0950c8da5f4dde101b6357baf13dfbe3a9869ced2f46f32f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:fd1181f22e0dcd52620ddd20d999d54eb50b5e8cd176b9b1099669fd25ab68c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:170308965ba2f937e946cd5066a9069febbec4fd3e2b40dd50708108dfdbb417
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:136b99c9e64b2c2d6af4d7fa2b023ef15175cef4f71dd40b151d1d192ef05740