dhi.io/erlang-otp
28-alpine-fips-dev, 28-alpine3.24-fips-dev, 28.5-alpine-fips-dev, 28.5-alpine3.24-fips-dev
sha256:e6db0d3cb8c399a96626752fde05b2f43a3cd85707f2d154bdbf17f1ca56c8f6
Manifest digest:sha256:02e8c3b71839f5fab2a4e8996622df0ed4281dcb6605a05b2c1f12d046719507
Size
41.25 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:28-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:28-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:7cd3810ed80bb37298fe38d48fe3ae409bd85bec0a79a9159179e426197ce28d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:7f64c8785a80766f42ab523cc9fa550ec4eafb08e300909fe93e12bb7f7b6e19 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:bd849abce11aefb3d1a2cf1423dda8060e075126db2c18460b6788cf477e0e62 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:4fc7e8cfa274932f47a3f1b94d9aefe1877f48cf91873037f7b22c200d8e7f31 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:9e12e2822a48c512982f2169ab2446219e7013d4a6942aab14798e01c861ada6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:196e044adc9ea8b27cd0d165fdd6ece206dfb1169d18a13c4a10cfb3749d947c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:f66e806b99d2baf7476e804d61b8a2aeef6d0c7d7709206501d6105ce4e2cf61 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:0f9047cb3064c36ea3b02726a94afaa9e86e29a8c7fc8200bf83a6bd5bf664fb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:c9de470ffc5274af3e28c27e5a85fef0e88dd14d1b473b76f84ea8c5ded1348f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:40062ca770106f74bccff2771a1810659fc79df9b69358e45cafff0c408c653c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:0f6a9ec31590a3b6d31e2b020cb0636adf07dd3b218e56395d4e7dc086648709 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:2e97e899642841bf44999486f764149e502b0735c5f57718bf4c1e555dcd0fd3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:ca5bab742734fac956c997b398889821d638ad059a2ad3bde5bb6884f0efc9cf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:86b85e9c1a1d6f246536706a25ef345e6f5a23874553651f1547b206260051ba |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:3b0a139d92b19d9213777ec8a479071e61faecc8206b349752d41294b31c2e55 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:378a7ef7d8701143f34dda3d2680c803b2b4ce3e78fbc30fb2101b0c862a5f7f |