Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

27-alpine3.23-fips-dev, 27.3-alpine3.23-fips-dev

Index digest:

sha256:84c72998edd26d5d9d030aa58d1db2e7e454aa190c21eaf8b5d126ddab644243

Manifest digest:

sha256:dc69b6896a97fe2e3b701be5151152a9cf8045c2b4b5debc502e6fbbf8c98b28

Size

38.64 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:d4eeff318c4053f80c66f103ec07cde78a56f8f9249fc78fdac5c4b9d321ae8a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:17355f52abaa0cb878ec7cb0ab56ed21f1dfcb64f33b3564a08242c9cd39e0ec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:91c5aedbbda1da9132df06e9c83fe91183e97d00961356055523662a1c0783dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:561f37e5ca6eb0e98611fe4f93aa3a7afda73203d127d94d00d8204e449c61d2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:bb5466ec7e0b85a09efd3c78133c68f30b7d56cd75c9b1109e5b2cea5c5564cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:06604b1c782222f37d988317b5378f833e4ba824b5eec2956afadb9c4d9ed1a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:dbf7d7a2af1012a5bc7f56519ca4c7ce2f1d5cb28f2c3ee4eb52dafe78d7234f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:275b4023ca4258a517278e58bafaa2b2b7d994d16aab78306f2b279dcf2e8ec4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:5e2a36e0475e3279b7a3a50ed95fad6ee2c9a9e601a59b67f99645d441ab710b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:788fe80727b5958a94ab9c6169a119cfed6c97752de4118833186cb98c9ad472
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:b6ce507fd99114255842444360c6f186a658302eee2e92a79f7970f5a48cefbf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:6d7092a8353bf446fca7d0440014b4db7196493c908fb9558dd26aa6729314d4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:848eb534fa494f981435ff40ac2048f4c7449fa80b216105261b4ea816a3d1c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:4d8e38fac3049d58785f6c42bd1725e25836060e44eef6be668e978cdf1b3e08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:2ab1a1df02f5a198c018e1b2376ab015ab8e46bd37947f52c2430ecee39d8fb4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:1a75798c16cc499f7f8b00b906260aa92e090fe1622f96589dcd94b6eebfddc9