dhi.io/elixir
1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.6-debian-fips-dev, 1.19.6-debian13-fips-dev, 1.19.6-fips-dev
sha256:00df5a92ea27049d462b31a43addd6326d61a55f223bdd428cbff1ab10b8dd47
Manifest digest:sha256:146cacd11ada0311329a97847bf307dfd70ab8222069b2bf751b993bf481aa85
Size
103.23 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/elixir:1.19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/elixir:1.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/elixir@sha256:f0904ff8a914db546c4c63791976b501f7fb4c96806725ebba2c1c451ce6cd26 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/elixir@sha256:515ec9cf2c9eaf1e1a7cab8adf066a91a305d0e038a0cb7561497f7d8abfd520 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/elixir@sha256:2b033c8604bd1277a4b41643116b989410c100958e9c99222e4d97c8b7698d97 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/elixir@sha256:ed2efba0365935d88a22975a1fd07e299279982f6297a051962990f042d89ffe |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/elixir@sha256:10613c291a9e4de47e7c582632e4d983843467f217cd7f16a6347a1d6037f796 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/elixir@sha256:7214b3563acb9bac6aa50b42703082e619037dc562ea723a87d1f021fd6ab02e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/elixir@sha256:3d2acbf9a847c6b7abe927d8bcda468f1c892482e635d0c7a41f2d0c0b737271 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/elixir@sha256:8f2187f49a1feb46179159ad02d43d4d34ebec9c331109a3e011befeedcca133 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/elixir@sha256:43963855d3fbb237e2c25bcf85ca8afbb83451e4e3475616312b25d633a94976 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/elixir@sha256:9c25b4fdcda6c85fa4ba49b39024d30c1469d9e5ef339ed1e220de72212c7c8d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/elixir@sha256:4d781f818c81b5bce2e2f706489825379ddbdd8b8ca65cd42b9a079c7a9a24bd |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/elixir@sha256:bcdafc2c4218edd092a3e9c117037087f3266f47a6ccb440a9efe37b814435f8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/elixir@sha256:d878edbc2682bcb1db7ef133d54f8fcbbf20d560a5f1603e3f298b1e3671834d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/elixir@sha256:26c22d8a5c04f16c5c9a8e09243bd5e3bfb197f3e6f3fb39b3bd0495985cb3fc |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/elixir@sha256:a2ce2ecb8b43ba45667ea0c58fc86d7efda9b81e99059dc5132799c445f35c39 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/elixir@sha256:a2525cf2ee9b7a192fdaf5cf21e1351bddfbbddddd5170d864b1a7e7a45aab4a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/elixir@sha256:1a1833cae2f30166682903fcd0484de7c1ba8e38a4aaedd70be488310e0ee36f |