Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

28-debian-fips-dev, 28-debian13-fips-dev, 28-fips-dev, 28.5-debian-fips-dev, 28.5-debian13-fips-dev, 28.5-fips-dev

Index digest:

sha256:f69a0a56b862820e373c714e965784da33f7c3af366a18ff56b1dbf539a76869

Manifest digest:

sha256:dfead5211eeb89e767e2621abd4435baa1f3ad4016adbc1a237ce2780f5a90a2

Size

87.72 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:081fe7fdfba6338d3e38927d4b7d2a571e5c64810351704e3974ffaa0c93e6c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:058b9f08c4a38503e77852451a37faf517c6b5e8971b3dfc35f3bb2ad4512d73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:d146b114fa8243e6b824ac600e588997f68e92cdeb63032c788b8461bf87d727
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:04889270ccb91441774ff1d1fe16165325875d5b9cb28683534baae3c755eb87
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:2204e595f22181cb2191ed56398763991226d5b2a6c840bdabd4f9304c5f92f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:b01097e5b7cf37e8adac646b28be463c235a267b1503cfb6e6e1df65fa1e218e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:81559db2e1d39e5b90b011e25b928808a69506361f18004c0e46354e13a9b565
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:0ad7dd405cc2785b08207f7d338df5b934bc9f2a9230fc030cde559a4164be82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:43e4eff9e1cbf34bb7b8497a8c911b80055229d00e84c1dd734daded3c705e14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:b28409268e64439ab18960f39673f4a7788ce4d934553a0d1f16e6875c6485df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:78b8bdfe4688cad735444c0cff11f3fb0d7dcb0a601eb5e2d47eeecaf0f5d5bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:28294f968dd94cd7aeb44cc0520911a4a094828a13a2d4ceedf0efb9cb88b363
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:d76bad2a1e213c6eddeba2fbdac4e560e2e4e644e56e70104ebc0a268d78072b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:d3cbb010a213a507456eeb5c728d1a11d0f12beef1b8270d9f18492baa7d8849
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:3de31e2328fdf622dfaeda344d3da423bc362a73b50c371cd5fe5401e0560132
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:9b91d31ade501fe812e371ad3a63d679c9b6763012206c7df7b65116440a15df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:0d2c50db2df5b49c85fef40ee5c5ee51f9030e3bd7228be2797cef099c06b494