dhi.io/elixir
1.19-alpine-fips-dev, 1.19-alpine3.24-fips-dev, 1.19.6-alpine-fips-dev, 1.19.6-alpine3.24-fips-dev
sha256:01266de6cfc3252b979fe16b5e1747d41b33d0d605a290c7491904fcfb2da59c
Manifest digest:sha256:6bab87885b3a737f2f079d19177959ec63d6e1bbe847e12badc53a4bdb1d3be5
Size
45.82 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/elixir:1.19-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/elixir:1.19-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/elixir@sha256:0ea1623fe06eba7ff3166744107233f78c23bc1ad57571ce570243177900326a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/elixir@sha256:44e43ba65d9128e892fc1efcad4c48fae46a953864682eeac61ce4db3c94ee7e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/elixir@sha256:63c93a0f69c3074848d01f3c1137151b4b3d1f7e9fbef0f0503ff21258e7d030 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/elixir@sha256:5bfd96c4cf0bf41febce5aba3b1a08e9fe896c73094f081dcff31c88559400d2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/elixir@sha256:dd0b089d77b38150db5e806d103a04f4cd68bfc8a5fbd7454ee9f7eb695366a4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/elixir@sha256:e5099aaf88675dd6b3cc9d42d3be555356239869fac517c98f34c850b6450cb7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/elixir@sha256:5d57460fd811abcf8357dafe2a75b76320c90fc0de88c292cf0036087dbcfe5e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/elixir@sha256:3d5a865231b8777dd718174d643c3f6388d0676fca4cb9ef7fb87071e5db1cc2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/elixir@sha256:690808a1bd2c0788f8ff93cccd4003bf29701aa39f030ed6636b6d4b2780bc0d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/elixir@sha256:05d6842907fff85e1c5f2f2b70d4ae3a0613f90fbe9835eceb738c7e4a32b625 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/elixir@sha256:5e1dccdaa64d980332c92dd3c39937f7d139440e32704d581b26e65b2444de80 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/elixir@sha256:d3e5b7163789b4bc4ba8e2f2cc4727bead725b8d1fe41a1cc10b2aa899f0ec20 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/elixir@sha256:73f03e2609dd8819e6606919d44043a83da1388017a5c0cd47dc1a178e10d00a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/elixir@sha256:767a02ba144f8f34b86f70961809f18ab8241400ba77dcfca8d4ecaffba539a4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/elixir@sha256:e0b99baa44484677e95bb6b60c0e3a1accb05cd772ce8d900d5623b52a8a7165 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/elixir@sha256:a83bd2f2a6bc339ed074605085b3f8d827dd6cc2782319b9610e1111ac2ca571 |