dhi.io/erlang-otp
28-alpine3.23-fips-dev, 28.5-alpine3.23-fips-dev
sha256:36de4cf8ebc366a9ab318b204f73229b8af9687a2a2c8ea80bf66384086c5302
Manifest digest:sha256:a5f7b6e41b017bae20d17e4adfd366671291270c3766bdb693f0fe9cd6ca4acb
Size
41.15 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/erlang-otp:28-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/erlang-otp:28-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/erlang-otp@sha256:8e833ca198b7244f870eb18ccb94a683df4f7e4847996edd3b75cf353be4fe98 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/erlang-otp@sha256:bddc49a5ffca0d075afb5316af6f5742e5422bd097c97e5f452327a5592bfd25 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/erlang-otp@sha256:a8487aee7eb3fc23ddbe637976f45926f17309cc70fea327ea9829207c3a4d5f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/erlang-otp@sha256:f02d5ff3ce29d16f5a59df768a8c7c6043ac9eb6c1906d6e068bb51236675122 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/erlang-otp@sha256:698fcf462825c5e1868aa51569e8a2b581759f09776e1b3dfde277c4eb58c43e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/erlang-otp@sha256:96cfd68de35d3dfaa5cceca0e8bf6ca5cad5d5b1a6362ce69ef75f8af12b0611 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/erlang-otp@sha256:9d53d5e3fa9a5a5815622274dca64c1efb375608d41d22417656faf5237ac882 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/erlang-otp@sha256:a371bef525fdc0950effcb486ff37ebd714de615a8cb1716e22ffdd08f849490 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/erlang-otp@sha256:27eca8444098c53a4aca8d5adb758b07b070e36c2fa635b92d789a6dbbcd6361 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/erlang-otp@sha256:a5c1e80657d27aff8702693efe53c2d9830843c85a329f0e0c6f022bf1c27869 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/erlang-otp@sha256:552989f59b2cf273bc178d53570a17ed326abdf777ef2441b0b43ef7017bc4ac |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/erlang-otp@sha256:6a57d8e6208656ce0964699a7799079d7fb577cdd11ce7ee191d4cf5240dd719 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/erlang-otp@sha256:0bebffa494c85549c894b187100da3e8fd74691e8d8975d700969e4437935a46 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/erlang-otp@sha256:dd2aad778b67d1bc941598186cd314eb66475cf9d361f1caa9889574070ac83e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/erlang-otp@sha256:5324eeb4929f9734df82bd43ea0f63459f9603c8c9d105a3e6fd8548ae68b2ce |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/erlang-otp@sha256:8024c5f6d77fffc76520aaa32e3ac51cbe3726b4ba47a7fc16de7b393dc9ee7a |