Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

27-alpine-fips-dev, 27-alpine3.24-fips-dev, 27.3-alpine-fips-dev, 27.3-alpine3.24-fips-dev

Index digest:

sha256:95ba3ba0429e411218986f1e37b44260a7aeaed6ddadcabe9867c725219bcd04

Manifest digest:

sha256:821ba0caf3be2c8159fba1bca3e807f6f2bc41dabfb6d29b1f08a8bd2d36dbed

Size

38.76 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:4ff82e480ba868624c14943a6e0534784157d6acb8a4c4c842b49501650ec515
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:e2101abc974b25d01a5b6c3a44da5f32b5dc9a8d17e8452f2cb4a8bf3c3ea397
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:92f116bb3ada74a451003dad6e198acfa431710d5b362860914c2d807af33342
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:a3b36d74ebad42f08e46f35603bf7808f8d716935f05959d51774dd5ad94af4b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:7eaee4e674b407f13ab7a10e7c7e51667c52e353f18ff5f494b97a7aa6d2a880
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:b6f91c840642a05fd8fd8faf4b46599794ced058bc0a470fef24cfb429282867
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:792fa73be819b4cb6f2f61be35aeaa1f0be6264a593086582a8a241e331110dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:100de44cba57f5a6eccd9791df13d8d1fb9ce28964e05e41e2922e70e5cc4437
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:bea28330a76295cde67ce253b08bf867f716b89d5fd9f0c51149bb178e4ee0e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:29420b1216e80f19829768c2ab790d612b63d137a2c798093c0ede9b1ec16037
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:d94a96a77063e9978b2790d93bf9f6dc7581cd1c23efda72c0099074211a82db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:435d6b1913a65bb75e2ccaa0e6c621b8fa000f83ce9e8d4f364f030ed2190f69
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:0bf8315680e819cfb2a1b7dfb17ad635d1c5b947e508282679c52c39a2a39da2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:fb31981c7bdbbdd8ba9275f2d0052d237c93c402b1b95732873a99a6a53d0a94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:b8c6cbca03405cbd1cab492fb2edb60dbbc891bc4a1836a598bb33ee5e31dab0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:60c3401473bb87a6dde3b50ee4e2549ad1b9aaa20e3607b91c46386b05f937c7