Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.4-debian-dev, 1.20.4-debian13-dev, 1.20.4-dev

Index digest:

sha256:9175634863be5c3db9c13924bc0d03ea18cf9c1d4b55d45fc09f7a3947a7f3b7

Manifest digest:

sha256:aaa938c403455a69bbbb728bd20fa1e121662ca51252fe9a35d1da5e63204cbd

Size

106.50 MB

Last pushed

10 hours ago

Vulnerabilities

0
2
1
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:7027615a9541700609e5f95a41e5db6b3a6fb863e34d6743b8fb90bb76dbc028
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:236df357829d5cec4b3c7eb41e6a962b3e60f52252183e1178f03af3fe648ddc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:37860689a71eedbd8eb1022e280b910e993571ba997794920474f74401aad4d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:c4600363d8b40035157b33359ee1509a978722bf36c17e087238bff13fe8b4b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:9336b1b686fb6147d1d5dbbc0e23252fe77c6efbe7dc1195f6a11b18c41cbe4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:947a188f67ca1458dc8b13e447e0e44598906ee90c2d407524e751fbf474b91c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:362546249a4750bb991f3b5452b58b3245e8862f23b27e80fc34d36c37247332
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:e36d65c0f73b8b8c63b3511c51041058bb1f3f2a177d14b50ceac068f2b2d7ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:31e108f222200c72b1fbcbb68fe5c137c47fee60d6a56764412400d57fb287c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:14277b5de178d128a6346f060f930924c3a2e4589f994a6123c31f9e4cc547c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:a3f07b4baf2f220aecb7faef756a608e94e3027cbc391b81e8261999f4257d7c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:9c894a7f58902a2979bab482e9f62f2471a03b3beb8f83634c590187b8f0e467
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:ff231209e6e7627abc95a742c5b4bb9073490c18defefb43a56bea009affb672
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:a2323ce0f1a53fdd778a90bfe5b660210c4924cccb5117419f00706918406fdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:5ca19e58dd98a42f222ebc25f381933fb0818f492d9e0affe6ceeb102dfa01b7