Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29.1-debian-fips-dev, 29.1-debian13-fips-dev, 29.1-fips-dev

Index digest:

sha256:98f88ce9f2ccb28492b058ad4035646069c2adcb899213c1ea8b3cbe67920905

Manifest digest:

sha256:a18007b90759f81179249cf0b9c74bf9b57b2320a07839308ae324734502dcf6

Size

88.96 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:62112787c73928c7921a08c9d479797ebd68f39cb1ee437eede59c10f5775c8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:d4013ecda7552ef27ee147b5d91f1645ca85a8d4459ed89316d0eaac86339b80
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/erlang-otp@sha256:cac61e73cdab3e6b1b926c74fd8cc06a7adb28490ee7c31dccc5efb84e5bf2c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:0aed7a1cc3ef3a58ae40c0899b2231294137934c6919444efddba10b76a6cba5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/erlang-otp@sha256:81c7cd83d21ff72b1d5641069c4bad890174f87da8bf4adbe652bc505a68d6ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:329db0026a6445cf261075f920f0ca088577b9cfd26a58442ee23efe04cee6c3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:c3fb7c73e1ce4d32e9ef498e96f1183df8aa532ef5ebca57d2aaacfc0e94ac2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:a8daacce16c60d1e2b847ad150a2b083a5b852e16a139c4c10da52b485d1102a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:7b23fc4e49e140098d43ce9a9644291f4184c22c7673fb06166dd973b8b77a8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:71e9f05146467a98c61846044b766f46b48136c1ee99a3cf1f1af747b713ec03
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:1a1b8d6807d9daf0c3232f1c585ac433e23475bc7d706530cde55378b8bf1dd0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:4fa942387f96f9f5882684faf6f3d1f875de935d8c2d95c37884c4a2001cc3ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:ce097eee84469deeb088ce9a7647cff3f2a5f706cbc54c03543c0c54f4cb3f32
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:4a740b5c5a089491f83c7fa86c853e5c4955e4663b8da8cd4bb6ef78cd0df18a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:95fd173f96038ae042e3a10d87a9c31781bc35dd27985f0fac92027b82928e41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:76dd309a7e726a3f24f8bfe8051dddd3d877cf7ca8e6ae65177ed7d555cd4c80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:f508fe2914cfe4ab2abe24bad34dd383d0f5a8ad994573545c67b0821e30816a