Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
debian 13
Tags:

1.19, 1.19-debian, 1.19-debian13, 1.19.6, 1.19.6-debian, 1.19.6-debian13

Index digest:

sha256:255b9ed247f3ebc6aec2bb7220e07798a3b3b561f623323d9228393d0006ec4f

Manifest digest:

sha256:82b48452716255db739a44a202ac1ba7af63fdcd1d0c4b06e0f2c56e1c7ca9d2

Size

93.47 MB

Last pushed

16 hours ago

Vulnerabilities

0
3
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:834da0bf0d153b074c2bf8228e1cdc44b99d5748064f93ed7933b8172e3fa16e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:b2ff5dbe1f298d001d3cead190186b996a42003464ece8d13f84da2063e8fb8c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:91cd4f2c154536525f87ba79205744c8c1670592c6cdc528e45c56dcd5cd5aff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:3bab12a47349f1a717b6dc4ea0f1e9c2944c52d65bd8cbb8a9c19663b2a46c95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:89e5ddfdb613657284ea1b5c73c0d53b7713a9d978346f86c51920560e3ab442
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:383a10070e9c004a0c51f3dd9009ccfe190e14888a734db06d598ad68236bd15
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:ee8f5594b59f16392faa13896ee677298af3fc1a6951c442759a7f933c0d534c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:729482fc19154575e7f0d3a337cf2b93fb035c5f74c47661961467931f823d75
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:4e686fd3af52c11a2ebcd8b9e08dad64d171004b7e1f53463d956b4f49647acb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:23de7886f7fe1bf99d79c3f63600957933b751950fd49b9e1ad047cb9312c663
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:000d444019a37d79bb5ec9256777b4f36312e03b0aa024f4bfee84d54ba993ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:58ed9c07abdbdbd5c7be0962effcc10968e26ccea6f5fdd7c1e0a344771b7b5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:e42b19962a147f1cf273c307d6a4b3b6fe91ad8b87088eeb3f30d3dd731e0228
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:9801abc2765d79b588bd4f9950ffa055fe014548f821055eec58ec42cc5f9f9c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:ae801c25e17b151b9a790d9426bb548920bc9b20ec9d909ace146fb7aae4e65d