Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips, 1.19-debian13-fips, 1.19-fips, 1.19.6-debian-fips, 1.19.6-debian13-fips, 1.19.6-fips

Index digest:

sha256:653f928bbf3ec4fa374838a8572ba7adb91fd4f9ef5160f03313f9dadcff7a3e

Manifest digest:

sha256:1ec35c968b14ef40083b677f66784c1ac5512e5b56b35bc3ceea925d87a14976

Size

95.00 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:3f0514674509d12e9e17a47a6d2f0e4402569252574f270c3d78ac712841a3ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:ec74fa1f8063c80fefa829f90dc2dd2e7ce3c126de4f3f0ae5e43d859297de84
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:965f380fd09feeef6a97f144bc9ff72e9fd6fbb71fc5ceecb99593d4d4148da6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:50cd6b45929f31eecebf33f1e72cf50e5317cf75c0331a6dfdf0eb2b5c65517d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:a54e4c84ae7c63901858d1302bfc6f75e9d44829b855c3b9d69f101411bd284f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:ce47faf1c6138f620461ec260f11486e52ce5c4a9f74674195368d1a284e356a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:a5412e4935ab596aadd60bb4d486286622e6749a0614074b4dba57845d3d8d52
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:abac4a9b346d748591b9038a70031c2e28fa413f4403863e42e38b4e77c6f8db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:dd1cdeae359b7429c2887839ebb7724e2d56a89c3cb136185803eb1c42b9ee60
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:45194cce78071f8245a55178f1940df0068eef86d40aaf7f58a11294180f79ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:86464428f212292d66aa5781b3ab824475d9bbd23ea4cdd3cdc31dc8bc0f1f70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:d9f3bdd61b9cf54579e79b9382e9c1a4cb54b5ca7e5d48a807150d9965282090
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:cb2917816e53373befb607491eca55598c8759686e9a6576f47ba5c8ad3506db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:08de64a06e2729e867586235cd0a950928013efd39550056123dcae178fbeb3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:ae7c6d0faa95fe363472fb94e023de7f1c4723c32a854a634c6c8ad13ec6ad37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:3b5e1b423a7dd3e95bcd509b3a98cbd5e398165bf1231eee89c6144e9243fddf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:13a4d952772cee4d6b9dbf08d394eede76bdd74665bca3654e8838c549c30331