dhi.io/erlang-otp
28-debian-fips, 28-debian13-fips, 28-fips, 28.5-debian-fips, 28.5-debian13-fips, 28.5-fips
sha256:45871b1608f245bcce6922d707e0171fbfd9adcf63245670586ded873a83714b
Manifest digest:sha256:7372a9927dc3abcb8bffb9542e7b239aa5226772e83c4130a7947d90e94c3660
Size
76.63 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:28-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:28-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:95154cf3e8dd480dd5ec22107cbfe38b45a4a3d6a39f57cce5629b425c1391b2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:bda15414b869d3a1e3fd86877aad53d5a45449d527e3b14d4559fe4755ecac17 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:6c1a94bd8183c6bb9161ef205946496595162bb3f8a5e713ff46eb65dd2d8356 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:96e825198436ceef1e63e5921d3a6306a4c29324a7b65d672872ae4974bdd1e7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:afe326acc46712dabd9898d313c44f82f8dcacc5f88ac73c1434ea96952579dd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:e428cb84337d6ec70ac02a611af1515be9424fe6c8be08d3f29b293a21d14689 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/erlang-otp@sha256:d0e5ee5322e1944484364643c67be34522c6f69003334121bb5debec4060c72b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:363032fb835e819fd59a87053fa1c70130fa6015e568f9fbcf5103caee6ab7bb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:89628b09b85b9f2e0c3ca7ff8b773921153f3e00f5b2a8d25c4a78b6032d6fa0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:45fdcd097c756c94377c4ac653153804f3c7979e34d672d73a4775202fd7ed0f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:bee6d02cf5a0e6b53e15f53157c4bc5eb7b46efa5c369ddd9d6f36cb9f9460e8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:d811ef3b6ceec13f886a1a787dc7e5656b373d048b426f2c28f0b404e8a34687 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:5ad2b666b159457e8e9c219e2f745757aa3ac6845e1d710e348ee67e5fbf3a67 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:852820d457a525f2b3f24fb0d74f3733654a9d5cf18050b8b579e7f5aa7d54d9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:44bb637734a53f3fc244b90dd2c60a175b063ffd380b6dcf5baf8785a523748e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:3e893617592c285033f336b0c4355c8007612e1b28ed880fa23a314dd0f94e80 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:0bb43333d7fe63709f3af77737cef5d5f83d427a1c18aa97f1b1278bf5faff81 |