Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (dev)

CIS
linux/amd64
debian 13
Tags:

27-debian-dev, 27-debian13-dev, 27-dev, 27.3-debian-dev, 27.3-debian13-dev, 27.3-dev

Index digest:

sha256:1fa1928f933ed2f523e2e2db0f5920bf9672fd6b0176b95171d61428d429fdd4

Manifest digest:

sha256:bb48997b67086326e9acc47896da2034adc1edde69ac5d1a202ababb6ed0a7fc

Size

81.91 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:59391c62772c25730ff022f480b2b0ca367913d378642c44adcf09480d86d8cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:2b6a0e5d50828791057fa669405effb1c964fbdbe0671b6b6d55759b2431c615
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:8a44103e2147c5c64b8748435f6cd3bb6cabe4af0da39839100d49833e9d2bfd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:5e1461f4c2ff04c44b41d3bfda9128523e424d98579891dcd71cacaf2b5eb3fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:d853969901d1213989410370429c3af702ba5855f67ab1ace4678d800f288bfa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:d9107242007345713e72adc9b5f9f3be051091efd87f646c2bab83df4eda82a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:551d0dcc617c60ad2235a881e71a06d4477d7d5dbd81afc12a8c366a1392f526
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:51244cb511bb4a90bd02a477f269bf9dbfbb385e7014e7d396aa1a8cfef178c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:86ff0e4791f5c5858bd9010a2e7bee80310986921a11d6a99ac76f7f5e95033b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:49b245c884763a6aa7fbf04646e6760fac806dcc51654d755e28ec7a88419847
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:0e4de933e7868761cc79182624fcb015b4848c88bf1211ee576062b6c617edaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:925ca975924306d7ef986946f5d2fc18da984530d478e461bded66d2c3c84761
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:5a8ee3ba8998daa1ff143cf33b517455396897e658df022b6590ca1ce1d2ec78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:dd588adaaf48c5182a1d16468f7969ab4e33e44c3307d05093d21e624c3fee6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:3915b3fa804ce4070aca5e900a56900a7dadb9bbda76af608f424e20acc4fe1f