Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

27-debian-fips-dev, 27-debian13-fips-dev, 27-fips-dev, 27.3-debian-fips-dev, 27.3-debian13-fips-dev, 27.3-fips-dev

Index digest:

sha256:d073f5dd26baced590bfffe3cb47b5cc316795ef118f2bce3428cf6ec7c03226

Manifest digest:

sha256:8852e08cff35154d36c122a526d309753524bda57dc3bd3d9e5c4c38d107a262

Size

82.72 MB

Last pushed

4 days ago

Vulnerabilities

0
3
0
15
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:6bd389c969af65c6e3d8d3c9ab80113a727bc520b590afe5092f90aeecd8f9c5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:d32e15f391aae104ed7ced836369a4f9ac37360a06d23bd4247cd35f45160abc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:ce363c3dbb1fe9af87dcd42942a9f2e2708ae93e9750d259d6424cf5e05a38ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:2be6e1eac65dfa78c0e800f321dd8ab8d94b02a1b89d9741a020fad3d15727c4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:db505f1763f9ee2db93a092eca776092d3c97bf9a8a225a9d35c9bbcbc6ab1e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:364c4020fbc1c17c2962028d29968e0b97894ca31972864df2362e69b95d0b03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:a676af2a950fee38c53134a373af76851be1720ba5d09dd84b8b9fc14ec589b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:f4d4c05d2c7909908f5af34ea65314af33e00faec4c823e291deb41be8d82aef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:e40c776e06ee8df89c16d233325a8b9477f4414a522bf1d0d582d163ddabae40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:1f9a62796f5aa813149d792105f20272ff39743d18512d2802c9bb07b0670709
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:4d68064c1a74861be66335c11422cd56c015fe322c325543a0e16f231f2da72b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:e0c27103a775ba0a867d25531a62e52f3f979c0dec8339090f70f06c8ee731ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:81b0ffa37219641723686e3dd96885994be43e0ddd16745cf88e2570002847ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:091cf4f02e4e91df926fa96fb09ca30bfba6462e539c1806e3b6d68fb10ee5e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:1ec29e8bac47471fb3831efdd67b8ae54f2e56c73aaede5602a3ed8763b54303
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:b32f3581a419785a56e9d49898aa68be9c2ab37e0e2964c1b2573997d12e62dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:b210d4ab4db62cc99371be85ba54ae1e816a0356362c796e23fb59ae9382414e