Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.20.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.4, 1.20.4-debian, 1.20.4-debian13

Index digest:

sha256:41c69ecf5c679ea51e16db686512f3a10e81a23867debbf88700a201ed6ecdc0

Manifest digest:

sha256:f36189198a6b35be890812b9918026b7d10b1cd0329fe41483aff6245ca5eb31

Size

93.74 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:980f2ca94aa65d167a6ef39df0a39e63aea47edfd5ad371c0c467e30d093c000
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:8552493a6ee5023886467a3a89cf35b4e1f62514e2caea29ec34844f71e4a11c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:3600bbd485980121f83504580d1f1e2725bd0056de1a0abaf7351d7fbdeee629
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:bf7458ff0f06e26fbe03ee256c0dd04e2bbdcae10761e7a2890eef33e79fc19b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elixir@sha256:a9a9b25f655cf7e9d1ee0b0b8929281cdd530db53f0bf81f1afd29255e6b2daa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:1936c3f0d77a6ae6e5eff483b59e4d437e46f2459535ee5aa96150128fcf4965
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:ebfa84bee7e1b4f28267347f54db59d00a5306b5a97cf63f7131dc1c7655f225
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:cae7a491bf66ed6988113698df65baa88d936c9f575966800baa95366c140ead
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:b30014eb4607f4acba77b5f52dca00f5876f2f6afb8d35680cb4dd5df5e66fc6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:d9863b2043ee138e03dedadd058228e84d6048457ef6862050a372f94c1369be
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:c6f1e60e149eba70575e03e690fc26284e90d009bc9f522c9a9ec366f0edca87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:9d76fc3360d966f640f667f1fd60864573b59cf8ca80e47eae1366909f5fb95e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:870c12be9e2d820398762268ac12bb290c147a8c27d369ba77ae752b7b9b4f46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:f699d679dac1f8406342dd4fcccfd3250b6459393d92fdea9793d31f17de8c68
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:85f52e9e4c890b21fb0cb03e7c84a8c1a2cd13381ba9dcc8659d90d3c9d9015d