Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.19-debian-dev, 1.19-debian13-dev, 1.19-dev, 1.19.6-debian-dev, 1.19.6-debian13-dev, 1.19.6-dev

Index digest:

sha256:192fe6d92c786c1d8c2e7d1b46a0e420905bd52a00cc748b00d26e708cddead3

Manifest digest:

sha256:5b1520d5b38c8fc9b81ff5558068b00835cf9e1d0ffb14e57bfed06a4a85e7b6

Size

106.23 MB

Last pushed

2 hours ago

Vulnerabilities

0
2
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:60fc5606007c7f5a4de9e45ea597a38fde3309a040ec01e017024b136d4592f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:50ec2e56a22f37ef412e0a6e2285356e7f1f496c681f3943524ea45c9ab4c79b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:cf7c09d36f890b20470172267809f14c3475be5f20203ab35e4a331345e84cf3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:3103d5a12e40db7118c5404b0278cd0848fa7423f4580a6fc1068e4fcbfd2945
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:3a703206bf54aa1129352086e381aa25c06ffec18b22c2c24bf67625ba402353
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:ac9b6c072a7d8e37b7d31aa7710153495c4a2522f9eb791d453b242bac4906c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:67f656b8dcb43e08e9a69534a077fbb5bcde818c37c68a299e05fc9347578863
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:4f5ffdd1cb57a640c6fa1a6aa3463684f88525f2182c8179ef2e2c6349a11bc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:fd27342ac412b6f9fbc9bf35f441aca3f9e70ddd8f723d4e0bd5369409402a1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:23ecee993ee93b7cec4f6e1b5cfc6bc180c3bf86782153ab557ff7df700d3714
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:212bdaf3dccc50866ddcbb205402b6d84a5c8131757b41f34f38d6aa9a3bdc2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:98c213d28eae3ea83d3d361cb244a1fdd0c95ff3a72afd0286491ea85703cc0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:9bb70819d768706bab0c8781946de83685e67c2efe62720684834f1aac2b2470
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:0375ddf876a59519bbe3e2e87c635f988416339ba363965de9a9439cf1b5ef80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:e148aed93c9441e635e57291986aba4a2494113ea15caf188d284a1e9da6a65d