Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

28-alpine-fips, 28-alpine3.24-fips, 28.5-alpine-fips, 28.5-alpine3.24-fips

Index digest:

sha256:11f801d06c3be1745eb351f8ff1c2509d36076e4d5be88b0aa1378ff7b16b7e5

Manifest digest:

sha256:c1add2fb9f265fa5f85ca03627453ae5c3ed06d381ed19b208870d4fab5bd413

Size

37.58 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:6f9378349fe762431681de1502d2d2a3f649542ad3e6d298457887c777031e09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:19efc0982d621590b9160c478d2c3710f3f3783b650e4b5d827f252e935b6bef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:19174faf2f488948183ad76ff812724460657ca83753106a2ce86540ae245255
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:63c711ba7614a461d4138d54312074343944f52ecae94cd31fc40b3851998497
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:558ec3adb29bbf72d94d3b5cae0e35c4d502614b7b3474abd69f67c959733168
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:02557b4f7d91e9b373a9a8ffc14dbb115a89bb06e9dbf4f6d441a059d09b0fd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:39c0e4b31179601f9acaa86310fc28c0e8ebd5ed202c4b32823eeaacc4bcdbb7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:8d00a794e6b8fdbb794cef21c879593c2c041b3cac7047a887becb77fdbdd0b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:c2400b3b8e5ae67732696ab9ba9318c492032788b5dfe6886723558351341443
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:b0d4f033201b8e313548421886945b761108ab88f69e8bc21a4f422a265ea597
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:5f5f15682fff3533cc01209cb5e0912df3da5cf3a41f1f1d6143b1c8c24d19f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:d53249db7d5e49a55bf1c615e9e2abd66c4acc268e077d1f1c76524b9b1ac918
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:e8518af726c388c7c7b11bec6f355a64c6092ded6121ca179bd2cb700cf0c72f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:569b754dcd32453b24cf70952949f1d8dc403c74f9bd61621add1eccd44b032d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:480fbe098e36a93d3a7e324fa0d9d9ae709352bb17adaa23dfa2e7c6c138fa79
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:04b0c52766b628ff98b5f05811e7bfec952e5e68cde5c9105467c75c9d35c34f