dhi.io/erlang-otp
29.0-debian-fips, 29.0-debian13-fips, 29.0-fips
sha256:eb9880afbabf98e10f779e570a2b8fccf18030d1bb42eb4ea5507aef324ef331
Manifest digest:sha256:e4a998f145a3293c9ae4c425bfe1ceb3a40941d860a97f61f7005f755c835616
Size
77.80 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:29.0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:29.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:056a50c2b3486e337469cfcf2e5a6bf80f391678b1b5b682e6d08852396f3056 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:b481d3c4b64bd2089f6eff3891fbfbbfbdade1599c162ddf55545dc8de878c82 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:5bb67b8ee9438a8c2a689b742ce3b905f94aa12288f08a1790a289b9cae119c5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:d0d2d9ce32eb7f75ebd295feea8d7d9ba16a6eb317fe8ef777374093792f51e2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:94dadbe37a351597aa3463a1a672601e54ec808bfb4433ffad85e0b41575bc26 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:f4da6a8c9cf1560d1a1377aceb37c87a70479650df4477f98060536e13ec494b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/erlang-otp@sha256:003e23c2cd07de585293ca6a5b12df50d67703afb7f4ae8a707315a5e6406b38 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:7b162ddd8d8064985affc0d65ad523d5b71041841073fba40e1c7e7e2602b4c3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:e02298818c662fa0900e995836f2697a77f702d9f14a3cb568392b0b0cb9c8f0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:5269c33847b2c7189eba0ca9af2c9485498d7f2e43bf86cc1233c97e419ee232 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:fa8b2a8e33529c32941b7b41396f29186adbd174d39947feb562ec9adcf16120 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:4f7898e553b03df377d87f75d423d6cb5a6cd5583a5661ff24b56ee5492bc907 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:3a9436fedc23ae0d7f4cd86569452302aee2fe1f26d6912c306e14c4470b0459 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:d4a18fffdc678d6fdb1e1a09d1e63ade7b8dee5de2ebe34dc53d0ea15f189330 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:2deb65428e2790adb8683552146e278c5aff11676a481718377d29adb1382772 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:cb5787226b55902f8b0a5328c93e3b66463389c074eb686929cfd1d1c96bc021 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:898a8613559510e1346ef1ce5bc64d899106704022f5964f2cfb9ca8d11a6a70 |