Sign inSign up
Elixir

dhi.io/elixir

Elixir 1.19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.19-alpine-fips-dev, 1.19-alpine3.24-fips-dev, 1.19.6-alpine-fips-dev, 1.19.6-alpine3.24-fips-dev

Index digest:

sha256:01266de6cfc3252b979fe16b5e1747d41b33d0d605a290c7491904fcfb2da59c

Manifest digest:

sha256:6bab87885b3a737f2f079d19177959ec63d6e1bbe847e12badc53a4bdb1d3be5

Size

45.82 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elixir:1.19-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elixir:1.19-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elixir@sha256:0ea1623fe06eba7ff3166744107233f78c23bc1ad57571ce570243177900326a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elixir@sha256:44e43ba65d9128e892fc1efcad4c48fae46a953864682eeac61ce4db3c94ee7e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elixir@sha256:63c93a0f69c3074848d01f3c1137151b4b3d1f7e9fbef0f0503ff21258e7d030
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elixir@sha256:5bfd96c4cf0bf41febce5aba3b1a08e9fe896c73094f081dcff31c88559400d2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elixir@sha256:dd0b089d77b38150db5e806d103a04f4cd68bfc8a5fbd7454ee9f7eb695366a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elixir@sha256:e5099aaf88675dd6b3cc9d42d3be555356239869fac517c98f34c850b6450cb7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elixir@sha256:5d57460fd811abcf8357dafe2a75b76320c90fc0de88c292cf0036087dbcfe5e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elixir@sha256:3d5a865231b8777dd718174d643c3f6388d0676fca4cb9ef7fb87071e5db1cc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elixir@sha256:690808a1bd2c0788f8ff93cccd4003bf29701aa39f030ed6636b6d4b2780bc0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elixir@sha256:05d6842907fff85e1c5f2f2b70d4ae3a0613f90fbe9835eceb738c7e4a32b625
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elixir@sha256:5e1dccdaa64d980332c92dd3c39937f7d139440e32704d581b26e65b2444de80
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elixir@sha256:d3e5b7163789b4bc4ba8e2f2cc4727bead725b8d1fe41a1cc10b2aa899f0ec20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elixir@sha256:73f03e2609dd8819e6606919d44043a83da1388017a5c0cd47dc1a178e10d00a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elixir@sha256:767a02ba144f8f34b86f70961809f18ab8241400ba77dcfca8d4ecaffba539a4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elixir@sha256:e0b99baa44484677e95bb6b60c0e3a1accb05cd772ce8d900d5623b52a8a7165
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elixir@sha256:a83bd2f2a6bc339ed074605085b3f8d827dd6cc2782319b9610e1111ac2ca571