Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.20-alpine-dev, 1.20-alpine3.24-dev, 1.20.4-alpine-dev, 1.20.4-alpine3.24-dev

Index digest:

sha256:64119e3e7246a392eb24c863def52fe6d858f18f558a4a0cc91237f33ef119cb

Manifest digest:

sha256:73e7fc785668d4f3967fd81a504e0be12c4e2aa9f9630abf6387ab86ee1b67c6

Size

44.95 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:b39215d88295fc79ad15bf13573dcb399c42ccf8b38fae30c77da97840e0bdcf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:776556290803895f1e55aa546d8311412435e156b64cb6dae682c6bf958eeacf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:60228898fa73339dd112ce5a218ae9aec3df617b9e04d6b2bd09981c5854e332
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:b3a3bd3b7b04b9a686ebd0f7beb977835745dbb8fa24c4743318e781adc3a0f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:21624c04c09f00b7b1cca2b7ee243304d02debaac4fa643c81fe257ca8c0536a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:4f6582ba4ac882b84891e6535992395551cf57c819f5f93b6b7f9e67c9a50f77
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:61957555b31ddd9519d2b537cebdf9a98a50e77b439ce4fb2585f1a6bdbc3eae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:726219ed50ffeb4462bc6069c623a91ecac171a83c9e276d6dcd5e9b065675d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:c930af4beef53603a6f0f82e435a82aa4c04c06188f099530397bd428cccf0d3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:f574470457c6527f168e43433a89704f88485ba2c20607dffd3138d8c8b22484
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:87801b8a4f39dec03f9405feebddd673499282eae300282950cd57a5748b0bf8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:17fa032270fcce701eaafdfc891a7d541441b9ee4c5c149eb24f4cd3fefcc78f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:6b1caee25e9ce6baa82496a47c5fca3349b5fd8e26b6424cd31016fdf5ab31fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:de2c51d41a4bf42a5e7c6d9aa5c943fe3166c4ae359c8bdf0c33fabbf38e05c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:11660b7fb81012118bef5213f34b0db9a15a3786d5365092f3f3ed4bc7a5e575