Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x

CIS
linux/amd64
debian 13
Tags:

1.19, 1.19-debian, 1.19-debian13, 1.19.6, 1.19.6-debian, 1.19.6-debian13

Index digest:

sha256:b5ae16ebbcf4c945f68edd72ee97e1ffed6998b06771f3978c3c44f5afc3caf5

Manifest digest:

sha256:decb58a2d9b0038bb1dc0e145e341289e2c1d6d1a13193c7cfdf397e03259c76

Size

93.47 MB

Last pushed

3 hours ago

Vulnerabilities

0
2
2
18
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:21e0d2662a2b7a5584e7c67e7fdbb80d7f405d86be1a2a55fdb5fb8d8766b836
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:8319d47638d365e476f7565b1ecf66f27b4a1e941f17e1c50db8076eb2725b7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:33676e9f1048a2dd8fe23e5dbe218b65f52585e247c504a8a6aecc078105bf82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:296342841c5d04216d1d380c3100a61cd975fb6efe8828f3b5ccefc7bed7da9e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:ee80f9dc609c12eaedd46b6bc09130c7dea1d85a1e3ace95b456640dff8e56f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:2c708cdf91a10ba6d3654ccd6135e5047264cae66e6d6fafde21e6547ef2c129
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:60839f41bf85211520609b0913d5de5595391585aa996362bbb1b7934bb52454
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:91b94aeab6efae80fb840765c6d4eb01a3d2218d5948801d8ac27f9f43ceee7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:7d961cd7ca49305137a4fdcd3a3e6573084502eaff632920c71805337de0ada4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:f43063819901f8ab51f6a10df32c0d6e261e9d2a5daf2adeec67c077166471a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:6c29d1658859324e5fa0a9ea01eaa87dc6ffba89ec416da7cfc1a04a8e81ec04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:71be6bc16d7f8ee0f96b59bd066cfc16fad83518386017527736bad3678ad9a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:4cb3e8eeca4e2ff758e867f411c00e39a19a956c5986f6feb6289a37bb414321
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:836667c09a40e4e223e2d8bea08ee7155abbe6bc2c573f33b3f6728471f542c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:e7cf78764e6349ccaa6a07569fc70563817e5b3ccaffeab65a58ad93bb2133c6