Elasticsearch

dhi.io/elasticsearch

Elasticsearch 9.5.x

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.5, 9.5-debian, 9.5-debian13, 9.5.1, 9.5.1-debian, 9.5.1-debian13

Index digest:

sha256:3e78b8c2eaa617988ec6135aa3e6a129a4c96d368854469234b4b4eeeebb3cc4

Manifest digest:

sha256:05157f960117f37723a25ed1280ad62854b440bd175bb533653d197267e33203

Size

713.96 MB

Last pushed

4 hours ago

Vulnerabilities

0
8
15
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:646ab06b19a395261763a49dfa06fde7dde4e2e1d8e70d6f5786fc5f9b944787
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:ee0d1128db950ef127587d474cf57988bf661713b8381ed306d75ee1097314e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:2e5ce7dbede7e7df5b4151427f0e4f9dafc787d1ea9c5fd231e0407cfcc24218
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:5169fa407b827d7b59b3760c848379b880715ab89a0d5ec38a1b1ecf168b5574
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:2753635b12f912fe0a7155f4eade227fef7dfff3e724bf1fed5d2510a4c98ebb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:fe68cae952b92834a993895f6c303b22636293e6699d4f793582c530c4c8cda2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:917581f777673a15e9a34b39231152bdbc2d4f17e5ee7775ae6a5cdddf3ece30
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:0df898535939952188c63a3d0718566757e5d30db60ae4e27b6f12a7c8116ad8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:4e93ba9df40e56f090506d14f0cd9ac2b8b5ed2f38c85cf4f57f73d00e807978
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:8f51f1e977a70ec3ff0935bf777e18791c18fbb8ae211b2578c714e2c13681cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:46d36d3dcab342a211151d300f1b0439e6cae4bd87063f098ec60bb39cb46b7a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:686509bc713c9245b3064afa72ab7d036e56b6b25e9847232a1f9c75afde3f79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:9ca483c107f1fb402e33101ad8ce939e9ce3235fe383d0dd09bbd1d0c50b981d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:085882118ea9fa62eb7f653936de7b317d2aee38fb505e6189011e4f7c5b1616
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:41f50c183d270ab71ce8a2c45d9192e1715a760d2720db15b6ed73de224db759