Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.4-debian-dev, 1.20.4-debian13-dev, 1.20.4-dev

Index digest:

sha256:8cdda304fa4651df8fc500967edc8bde8f8717c43e01f6b74d9639950835bd26

Manifest digest:

sha256:1e279d303abce6095a5cbb1093660fb30662d6b9a11e85f187073d1e8de17eaa

Size

106.51 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:c87530fc15c94579fa4e9ea168864ae4462070895acc43e21f3fbb385f7a52b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:cf01a505ab8a91929b2cbab835862eea158ba72f80c95a9836bab7c1306d6b83
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:ca51d15e080fb4eb5fd2b10195d162d55af0488c5de079154730b11318e02715
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:5f10cbd3ee54e3a1cafd6e98a523be02731db8f0e7267b0069f7d4c8012e1196
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:27090a07728e8bec2ae881471b737b4b809de2bbb97d76c172dd022d14973e2b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:e5173d5a50585b1477c0d9bac06d5f1248548148312d383d380ff33d74de3168
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:e37d7e9cbc28082259b80ce354010e7b152f542a9ffc642e11bbce8aa85fcb10
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:471c040ca3e0fbfd61bd162e73490604b2148ba2b3e56631dffaaef6fe4af0b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:2060ccded3f2bcbeb50ceaecf67ebf1bc9ab377f478692e2b854cac1b68aea9a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:eee0c7a3bffcfc8af1c52e061a8b4a6bd6505ace3cb6f4f44f1d305caf091505
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:0466d9b260d184a942fc39175562a6abe1d04860b594b23086529563896a0915
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:2af896a535ccc21fe1e3e1b7d388972a0fbeb373e015c6d60e9329807bbb4329
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:a27334776f0973ea59f262cc63944318ebc23fcb7aff4eb82dbcaa900647c898
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:52c5a3a7b1262456565da7d11635a8d54ddc10c9b1881f44452358ec0a9217f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:672ee720e190bc87b3fb853c971771d4d4fa0e3a238338a203aa692dafb6c3f6