Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/arm64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.20, 8.19.20-debian, 8.19.20-debian13

Index digest:

sha256:0b8852ec20259c5f21b344ce16d36d7d8a43f516a44f7ea4734ca039962bf8b8

Manifest digest:

sha256:491265eee021aaba7ad9f2f473e9609696d6c5072dc9db3853f1788ec6fedbfc

Size

468.20 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:dca8bfbbdeb6d7bae9a77bf40dea89d14dceb90dc1b52e490b5cce162ff4859b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:1a6d46e231253daabe91d1ffd425e0d5523c61cbb6b2a3dd44b9890f2e970546
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:e7426954932a150f3c702cbedaae3089c42483139bdfa75baffdd661457aad49
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:2c25f6e8bc70ca1dcb7c06e5189ff602a0c6b862d7a9a5c53c0223c44f71cbb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:1701a8f73be1365dcca3595f95f8068ff2b5fdb69bee3d419335e0d803b31ea8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:e622e14a33634c22f812dbf6b0d14a675f380fcdb3a50e63032bfac3eb71703e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:fde82f91969ba35e6348f02959bb38f5bbc00f98c95508776d14224c2fc1e02a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:1a67122221f99801c627209ed5f2cde2a5fa9d51cafbc597779892b925bc348e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:13775af78b672b3e3f30b17cc1eb0b8ba9702861b906eb7b74ac4c561da5c30e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:523c7dcc8334bc50d4105d0a108c56904aff0ca89324826520f5f9907a7ca668
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:9f3ec264dbe38bdbef247f0fecdb74fb31e30b2bcab1fdf305b19df0cce7f558
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:9aa58d9bca3808790d432123d8a4956f9fef0368ab43a38365c68a7e0ebe6df7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:2e1c4e3a8b7e800e9525fcefbb313343984b4debaf8301c54f0701e4092499e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:6cb60d0ca1e4e2930eb92296721e2a2e02018421196a9000cacc52c5ac235638
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:cedbc96c4efd25bbf4ac8e09c76441e9b7504bb361afbb4bb9b3d47c99ed9b03