Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 28.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

28-debian-fips, 28-debian13-fips, 28-fips, 28.5-debian-fips, 28.5-debian13-fips, 28.5-fips

Index digest:

sha256:eff508da620aa8cfe148a944d7e8b7302b6716007ee3cd8cb207d5ce22b74734

Manifest digest:

sha256:36f22637a2e0fbabe075f4615f8133c36c73021982bc5c6ef4dc91a5fb5b39d8

Size

76.63 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:28-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:28-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:9865c6ac48008e028878df43ff26a0902112f04deaecd50b2e3452d3f3fd9d16
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:6714bd2fecaa8b0448639c6d3eb1e6f14e3880fe5acc730aa2518388475722cb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:1f72ab7e7554e06054b1c8f62847a641159d7892a45f4d39009489e5885d3aa3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:d4a3189aab9d99ad072186cb7585f609effcb031320a33f53f5454746857aac6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:1103757159c571cdc388b58527bb02de520dcdad2c40b46549c9e8e24810e71b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:7e753f2692e1d5df069d18ecb8ac79f944875b36fd24b9d1cbfa3237710a8c64
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:153d8b0c0688f2b18d4f83f27b121b8de516ffece134293e6d8fc0de91110480
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:7a18c59df78b8c9503d1b1977000127ced5006bc2e2ba860aceeb96dd7bd7195
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:b417577bf5b688a7011d2258fe93b66656c21d3954d6a1a6fa37a24ed1ef6762
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:881994a7a4b1acd7d9782a5c5c93db4338adc7a108855de481f73462e813485d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:919e3a69669b554bec19d581960bab740f2b773d582ed4cb1d221b40674d53e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:91998cf1ae397ce131d5c3c8aee00ed884a4ccce9427c345e600ef3ec14c0f54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:3656e317a7b9a50019fdb9246fad683c286d871235e4dcdab9ba6785f674355e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:78fde0386a8b38213e14f4fc7ae6896c0b001168e85f35c78bd254131914691c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:9c006d5f8005ad57a2a7afbf709194d374d2735df287dc00ec7d232a71151174
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:08e9beac86c3577c2ab3a750cf502392a1ce88d18c964fad7570f1cea1e005e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:04fae085c8e114ea29bdf9e08be5187e2f58fe0301d863bd102a529f7e408f04