Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.4, 1.20.4-debian, 1.20.4-debian13

Index digest:

sha256:0e8cccc51876602fef810451a16e6296d50f396e9d327805b4529266092da980

Manifest digest:

sha256:cb2d51b543b214ba6fbaaa5e7a840728fdd43f1c90e9929e36c34801b2cd8817

Size

93.75 MB

Last pushed

15 hours ago

Vulnerabilities

0
3
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:2aa8b80a85129a2f7ffde73f8c195b8f22d7159929e4223a0db3b4c79b1c2f89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:9057cfcdef1a3d67585b4d3d2630714c69219295fe58bbd02ebc7d7b440410ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:8df18e672df1c8e87bba3fddda3e653d85470d296680b0722ea1c24cb601b705
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:2d9a311097a76982feb2abe5534a1a1f3f5e88f11ed8c51199ef5ef52e609965
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:bb31f0324bcc188795bd535d6ce2e0be66d60c58d201da4e714f695f9397658e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:1ef4f031c5acab00f38013a55271c8572d2f93a3cd238fe36e55901383caec8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:8d926622633d280a6071a6598c5df95f5acb529d215f2ca33b773442c478cb68
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:001468791a6c4959aeb6b4ea0e00ded535cfdec28d7ab6a8d9dec0716e3036c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:fb066a8d72377b19af9bf77b2e743db3263b753a820881c3ea47d2895c65f703
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:1ceef0de9ffdc5e412b518343c53c98c3ee2b4c84c5b3d8bfe540a7d7d8afbfb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:6ffa8910bb0c777ff1048908286158ca5b6cea9ca30925b7ec3b936d7ed51d1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:3f0587f6c5bac46de0ff2130376e1d3ad2d869c7a9a4ebec962a371fb5ad5835
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:a5d5c0540a54ff8483054aead896e670c81ce01bb4a5c525afd947a78dc6efb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:e3606bd4c7e20c4d52862998c2ecab2375cbad605b5217610de87fe84a5d2e86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:3c7d4b532f6a424b92b866d25510570b44e516b9a1b51ba2eb8b251d7c3483c4