Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.20-debian-fips, 8.19.20-debian13-fips, 8.19.20-fips

Index digest:

sha256:274164677c628766677f92e5d6fa09995b3b445ac6bd4f25d42ec02d58f62e84

Manifest digest:

sha256:dcff2c4f6f7b42591828f667f00c09f250ae11d29745721693bcd5d1ea73fc03

Size

581.11 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:c9696d7723f2342bca683c2ae3529cf202d409bf343d713f5dfc13991e692fa4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:b21dbb92cc53c4a441416b9fd4484a9de4e766afcc34ccfb4ecd08588092a723
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:87c5ed41670f9ae949e819401b564b8532594a3929849fdc8053a50b68a7a17d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:54bcfa3d68e13276ee11316202846cf5e85696fbeb676e0442ca305988b077bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:3e3010e8dc8e6abb7be4ec240cde390b8888293775f50eac0d9fe46c43725789
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:3c0bf38dae08b352a390d6a5f566bdb85918c153ebd52b45ca94ef3e83581445
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:2f8f8fb6e95241a953e213fc53f315e75042f4acee52d1a63c955f276948d30b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:19252b20214e2888e49a13d3a9a55af0dc517acf01ad928dd6dee0d19aaa0299
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:ada2feb4163734d12319d16a8b6d41e2fef47a923421ad5f03931ab2d2b666ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:b2cae806f72d047dd794f6c5e4da93148ecac6f609761b3db7c5967055dfe8f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:b63ca22da3c9d6adcf9aec3979bafb5bc0501a00bca794659ec06349899bf20f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:270dd4912c6b56cefbfc09b499977706fb8d250d22cd8edad4e1cf634925705d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:10c561b377a1b4e95b9a1137af85f3480a5cfcf272b7053131a3bcb3633f0673
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:ddeed0795a5121d8917020b886573cde0c348ba24f39fffed9a8fa13dc7f95e6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:cf213ed2c0340d9a18d83bdb68c97a2cd87aecf017e65487853f1b1f1294eb6b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:a0aeab289f6027e9eb44477e854f06b63e5ff04aad9b70d7f21eab2984b7dd8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:1dd9e3c0205d76a3cd719294c237e62cacd84c09f806603eef3bf650c81c8db9