Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

27-alpine-dev, 27-alpine3.24-dev, 27.3-alpine-dev, 27.3-alpine3.24-dev

Index digest:

sha256:d8c05241a404628fc8db135c852da646d2178ca48b6e316c9da83e1fd1019030

Manifest digest:

sha256:2e08522df6bad3c4f5323c003d071db73f5a0028513c0c761ac97f37d9c0bec2

Size

38.08 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:fe2b0801a2385c69bd5592be7c2f4e0a351782a9fcdb4bb0bc6fdc30c88bf537
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:aea1b61a1c1a95a187ace399379b4dec84048e5c4aa9006499aa02422a885b33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:ed37df2583efe35d5c66757637a5d10d287e3b8d7c9494d69504d51619145673
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:5fa69697ca1321c538b8597501d167202c04e24bf768b70e58f7e10f4e0c58b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:c0a0cb578c9cc88c8dfcf2bd0d547823d081938962c62b9f0df0b5875ce93e5e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:165df5ebe074dd5515e9ff1893184713725a4ce2685641038fc746cfef38217b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:178f7f2b43b0665a38520258126b6e8acffe5e3dadf5c380fa1ba6f04000db1a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:d1561c351a99dc7065b8ce7fdfdef18497279e037b670063313b375b412ab98d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:c650faf1841e91f6f2a735b29073ca3d1203cb70f88d06d7ece30398bdc46a40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:806e178d435ea95f93d2f0880b8182d67a9d58d41907f42148551825d869885b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:2fb42e64be223a3ac3832c5577f45ad6808bfb78232f7a57cf7200aaad0d3f3a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:4c9553ee671853ad5fa006c64315c80525ff201294b6191ce774b32f4bc2b99f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:7804d452dac240fea9df47f3add2a852d41efa982e095b1f7866d18434ac9ded
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:e0ba2ba77fb1102a0f087066d3e364fcea21bccb8a2a04a13eba501312e06fa5