Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

28-alpine-fips-dev, 28-alpine3.24-fips-dev, 28.5-alpine-fips-dev, 28.5-alpine3.24-fips-dev

Index digest:

sha256:e6db0d3cb8c399a96626752fde05b2f43a3cd85707f2d154bdbf17f1ca56c8f6

Manifest digest:

sha256:02e8c3b71839f5fab2a4e8996622df0ed4281dcb6605a05b2c1f12d046719507

Size

41.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:7cd3810ed80bb37298fe38d48fe3ae409bd85bec0a79a9159179e426197ce28d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:7f64c8785a80766f42ab523cc9fa550ec4eafb08e300909fe93e12bb7f7b6e19
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:bd849abce11aefb3d1a2cf1423dda8060e075126db2c18460b6788cf477e0e62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:4fc7e8cfa274932f47a3f1b94d9aefe1877f48cf91873037f7b22c200d8e7f31
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:9e12e2822a48c512982f2169ab2446219e7013d4a6942aab14798e01c861ada6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:196e044adc9ea8b27cd0d165fdd6ece206dfb1169d18a13c4a10cfb3749d947c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:f66e806b99d2baf7476e804d61b8a2aeef6d0c7d7709206501d6105ce4e2cf61
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:0f9047cb3064c36ea3b02726a94afaa9e86e29a8c7fc8200bf83a6bd5bf664fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:c9de470ffc5274af3e28c27e5a85fef0e88dd14d1b473b76f84ea8c5ded1348f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:40062ca770106f74bccff2771a1810659fc79df9b69358e45cafff0c408c653c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:0f6a9ec31590a3b6d31e2b020cb0636adf07dd3b218e56395d4e7dc086648709
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:2e97e899642841bf44999486f764149e502b0735c5f57718bf4c1e555dcd0fd3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:ca5bab742734fac956c997b398889821d638ad059a2ad3bde5bb6884f0efc9cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:86b85e9c1a1d6f246536706a25ef345e6f5a23874553651f1547b206260051ba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:3b0a139d92b19d9213777ec8a479071e61faecc8206b349752d41294b31c2e55
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:378a7ef7d8701143f34dda3d2680c803b2b4ce3e78fbc30fb2101b0c862a5f7f