Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.20, 8.19.20-debian, 8.19.20-debian13

Index digest:

sha256:0b8852ec20259c5f21b344ce16d36d7d8a43f516a44f7ea4734ca039962bf8b8

Manifest digest:

sha256:e227858b8778c95bb949609e0bfacfae72b12bca90fa4734d41aa1d37170ddd7

Size

570.66 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:79987d38360eb967a4f1ec3beca0caf376a5a6ec1d33dbf85fbf01cf95e2dd7a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:8932cd24b2f3f921440ae6c85f15208e51733e207332839a1d66ba1ab4441c68
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:3f732587e159bfa06b49cc76a2213e8fc010e84abc52e31dd813d2fc5489d945
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:aa38c25dfa1043f360acf4a0a56d8fc8024e3522eb137317592f4a00acc77815
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:7ef499806dba9d903d31f19de9cb55f8fd25dd06df0221e4e59f0711e65fc2e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:fec282514180f4716c91a3528615c64ee6e7d19c7b5f0fd8bbbc154eef6ac3b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:892cba87d964f571625604108c7284ccf3f373ffcd807590421868d7fc7a11be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:12be0ef0b9b6c2fce0be6d3600a0ef708edf81fb0dcdd04bab512272fccdf0c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:c40a2be9e6c189a8f006c5ffe2cf4e1903503a6785568babf480eb31f013ef98
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:7ba1c7b2ba527284920425d5f1abf7815355015d01c895a0f828b6b6acd2a297
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:3819189e62c68ee94cefe1b26b4ffa8b56c6383a4f62d4457fe0f16cc80051ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:13c80a25d2dd74c2fd49bd802740c4fac3aa775031452fbc4bed51d8cd374b62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:076463d4b66f2ee73a2fa3189f4123504bdb65aea2f938cfeecd3270a1f40d0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:e9cd524f72f67a4ba1ec277e7ce21f8576fd539b2a917b6b3c363edc07d0c77f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:fb9bfb7dfab2692609bb5c001a3b1fcfec1b1c3cc997aa082674e2a2c71906f0