Sign inSign up
Erlang/OTP

dhi.io/erlang-otp

Erlang/OTP 29.x

CIS
linux/amd64
debian 13
Tags:

29.1, 29.1-debian, 29.1-debian13

Index digest:

sha256:ee41df13746b2bd5a13103d45718a4942803ed4e29ce48eee350f61d0f9bbedd

Manifest digest:

sha256:19694af753b0413c95c0d5425db580eff2eed194c5b5ca04f1e2b01e64e4792e

Size

77.09 MB

Last pushed

2 days ago

Vulnerabilities

0
3
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/erlang-otp:29.1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/erlang-otp:29.1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/erlang-otp@sha256:73375e2eecda01d384b0ba25d52a9879077acbdc8cd8057219cb5b6982831e06
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/erlang-otp@sha256:f4d395f3404828c67b866df521ab85ee0c8c58f539d99f0a3b0c1e2e80a69c29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/erlang-otp@sha256:c54aaa172db2840d68481794c13c300da52acacce3f5e0a332066fff1a5d846a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/erlang-otp@sha256:d9e7640da9a66847e4321a71aa5b3effaefaeb8bd7729cf049ff12d5c3829643
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/erlang-otp@sha256:c37acac190a2b33a80d0e9e1715dcce5b3568443177ad54777300d6599b5bef8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/erlang-otp@sha256:f82af7370eca3e0939ea75f39abc77055a8d2005a50d3657213ecb3564837c28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/erlang-otp@sha256:945e4c6d14dd815c1a8d58b8dd38e8d74b376b8ca011409a75d905b708737497
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/erlang-otp@sha256:d5c716ad5cd30a395f4503216460e185fafada62f161a068ed118f62d67af2d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/erlang-otp@sha256:c5a44f9195cae50d5647ab10633df9075680b2123d8ba01d6d94dbcaf33fd4ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/erlang-otp@sha256:cb0e5e0096ed0e9408b7c84cca13173d1051d6342a1af3897ff7f0f4f3091233
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/erlang-otp@sha256:9851ab490ba8ac307e616a141f94f20428f7f452f2cebd2a6872900ff50147f4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/erlang-otp@sha256:16c91516134970183a9eecbb05435a31be756539fd79b0b68977ce87d504b69c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/erlang-otp@sha256:51b541575ab8fc3cb1955a8c59256510d30149754a5fc596b35a94236e6f5164
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/erlang-otp@sha256:438de540519518a4043fad4498df1c262e700cd56b2b545b0d3c12cdb7eeac02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/erlang-otp@sha256:8daae8a9f94c51e70d76ed373b4a3b7ee54e7f2a5c0cf08ab4875cced1adc46e