Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.20-debian-fips, 8.19.20-debian13-fips, 8.19.20-fips

Index digest:

sha256:274164677c628766677f92e5d6fa09995b3b445ac6bd4f25d42ec02d58f62e84

Manifest digest:

sha256:632ec742dbcf4d6f90166d557e952683cc1802ac8979db71dc8c948201a9bb91

Size

478.53 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:5d808d5f4fcf38102cf7867e15eadb51b38f7b9e14d911ce75d2dfc4845cb9c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:fc9f044857fec043927ce4d1eec72e760bf24211e6f9768627788fd308277419
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:f9c607c40a7a188dddac545c6410000df035910e8d88d25fec938a96ce4a51cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:a36eca676a5370e15dabbc4adb21e898cca5f2ea47da408b9cb052861ef0b290
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:1fdb8a9ddcf5d53dfc18ca66829e8813d083ede598f85cfde3cf23ccc9bbff55
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:4b6235ceb9037805a249faddbd47d4233a7d98cbf310faf461c0b2fc0f5bb60f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:29170aef43065db18e5c9c9e58979fd52173af0d4ed688b9eea81fb7835ffab9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:316354fb452cb1c1708ba5bfede1d2fe66bbc8e19fe60964ea3b824e75367b30
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:1230f60e5d1c7ebc8298b8fc34a0eba05b4db5f399917fc87eeb5c9505ee375d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:18eac2a94dd29addea0d77d7984712c576ca38c9a123ba9333a1d5901cce33ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:15440076273cca380b512f3a87a45c9852cf594b128ccadec7c64b9396cd5d2a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:d5d86c990cd15c30be24712896836a70a865824b78e0e43872e9f32f8fa3de86
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:7cba94bb5886f37cc840e44d29a65a3abc0b8986995a3bd59b079081a5fd7b9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:4676d801957a68cfce08211fd59eb8fc94a73e961ba2b253675ddf727bdd3c42
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:37804c01d0e51918e4f9c4ed2b6c490407201bdda4b10a1a22b5eb4aaee78240
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:d514f317ffebce3de2ccf877eecdfbd44c1e7bfef29e281fd4afc0d3db9779a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:717e6cb72c146590682dfc6fce6cbd073e0bc064cef53c59ddec159ce059a287