Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x (dev)

CIS
linux/amd64
debian 13
Tags:

29.1-debian-dev, 29.1-debian13-dev, 29.1-dev

Index digest:

sha256:17c84c8bf345b1caea1c522846db8ae4c0c4cf7444a19995beebcb0aa380322a

Manifest digest:

sha256:2c6d35dd836a5ced2afe7008162d4f369cedcdfaf41ff337fbdbcc74d0634827

Size

88.16 MB

Last pushed

1 day ago

Vulnerabilities

0
3
1
15
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:b25a9aa16855df01d59d66e2d178c930a7e591410af9563e5445351231e3a6f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:ab42a1dba93ae477989c21d7f8beea7908f1fa3400e330771bbd744364ecf697
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:883497d7d9247fff59d23bb83a057b7aaabe1fcccc261cc0ce3fe6b617b4c5d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:33f148bf142e63b500d7851a79b9bc9cb1822d3811618dad7b966ae4bb274731
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:74ab0113e7846609f319f2de5dea6a77de2592b3b4b3a7da83ce1cfd009390ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:4a99b92ec01ffdedb993d075d916ff94c7c6add71dfc8df09349513881de9f87
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:055ab5b7291933bcd96bc9d113f26e0d63aa30598744ddf742005378a4b76d9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:7b52c66b64752da705f0d54eacb73fc27e0c6098c80cf560e3f1a801b90801f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:9671d326349e372a3e73e758c8926268a3ebc3ef0e4b1e33724140da5a8d47e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:81ce32398482a769afea92cb96c91bca158afe483dd6bc35563d672be4fe01dc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:4efc8fff59ef476ac18af1da42bd209400980a02faafe2fe8eca274b24bc6d7a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:9a5dd0d75988bde7b9a23f836646c9d9e72ec6fa4fe8ad89cc9f5d6645cf1b8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:f502d6fb72f2bda382830010217295b281e364e8dade738ce7460c40732275a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:0f2972c7d11acde878ec6b78e6e47bb75b33d263d421f06beb3864420c617573
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:615c2c77201dc44ff0a3d47132e13ce3be8872e9012b26d8d17db818d05e9948