dhi.io/erlang-otp
27-alpine-fips-dev, 27-alpine3.24-fips-dev, 27.3-alpine-fips-dev, 27.3-alpine3.24-fips-dev
sha256:95ba3ba0429e411218986f1e37b44260a7aeaed6ddadcabe9867c725219bcd04
Manifest digest:sha256:821ba0caf3be2c8159fba1bca3e807f6f2bc41dabfb6d29b1f08a8bd2d36dbed
Size
38.76 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:27-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:27-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:4ff82e480ba868624c14943a6e0534784157d6acb8a4c4c842b49501650ec515 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:e2101abc974b25d01a5b6c3a44da5f32b5dc9a8d17e8452f2cb4a8bf3c3ea397 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:92f116bb3ada74a451003dad6e198acfa431710d5b362860914c2d807af33342 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:a3b36d74ebad42f08e46f35603bf7808f8d716935f05959d51774dd5ad94af4b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:7eaee4e674b407f13ab7a10e7c7e51667c52e353f18ff5f494b97a7aa6d2a880 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:b6f91c840642a05fd8fd8faf4b46599794ced058bc0a470fef24cfb429282867 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:792fa73be819b4cb6f2f61be35aeaa1f0be6264a593086582a8a241e331110dc |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:100de44cba57f5a6eccd9791df13d8d1fb9ce28964e05e41e2922e70e5cc4437 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:bea28330a76295cde67ce253b08bf867f716b89d5fd9f0c51149bb178e4ee0e4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:29420b1216e80f19829768c2ab790d612b63d137a2c798093c0ede9b1ec16037 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:d94a96a77063e9978b2790d93bf9f6dc7581cd1c23efda72c0099074211a82db |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:435d6b1913a65bb75e2ccaa0e6c621b8fa000f83ce9e8d4f364f030ed2190f69 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:0bf8315680e819cfb2a1b7dfb17ad635d1c5b947e508282679c52c39a2a39da2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:fb31981c7bdbbdd8ba9275f2d0052d237c93c402b1b95732873a99a6a53d0a94 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:b8c6cbca03405cbd1cab492fb2edb60dbbc891bc4a1836a598bb33ee5e31dab0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:60c3401473bb87a6dde3b50ee4e2549ad1b9aaa20e3607b91c46386b05f937c7 |