OpenSearch

dhi.io/opensearch

OpenSearch 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.0-debian-fips, 3.7.0-debian13-fips, 3.7.0-fips

Index digest:

sha256:627297f6a60c1293d04456a3e44abffe61cd4304d7803b7b8befd73c08b9768c

Manifest digest:

sha256:1c847ce4bcc1c1c188eb46564ff2b169c55beb00e193115c36562a668f94036d

Size

925.77 MB

Last pushed

13 days ago

Vulnerabilities

0
1
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opensearch:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opensearch:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opensearch@sha256:3d737701e76d26bced9ee9e21e9447ba6a8b07ef90f02d86deed8c0ab70740a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opensearch@sha256:d2c412361afb3a345e58c2ed44f42b2c9a4311c00b3054f09cce2f893296460b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opensearch@sha256:cc42c76deec7eb16adc5d7ac153b4ae3ee227d5ba0cfe55631b6313bddd775c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opensearch@sha256:b56529b2763029faa001c0036be7e8ed49e9ec3a0cf128736083fa00337ddb49
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opensearch@sha256:c5999e0c744121c9bac8f4606cb8f9e31542fe07c15917ea6cfb1f70c7e5caa5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opensearch@sha256:04de9344067b4750fb7dc96799f33fad0d4ac470cc88d5f9dff59359bb1c7d74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opensearch@sha256:11654918be5f3ef8bc10111f4f53c40fae1d7cd0491cab71f098281300c966ad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opensearch@sha256:7209edd16bfe7a0cb88ab518ec0352c424b3b597deb23fea1ef90ad7ed8656b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opensearch@sha256:fc88b68f980404f50d6985a3caed0991b1e1f6d42d685dcd887ca7d5ec68132d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opensearch@sha256:288c31170e639748518544e4157cb89a289d1d58e44ab8962813806e24efcfe5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opensearch@sha256:50a5a1d4595ec29338013f134641d070557d0fa5d735d86404b112db9172526d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opensearch@sha256:769e4475f3eb25f95d72ca38b79f8cfc77172a96f1c5b35fc5595ad8ece380b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opensearch@sha256:2d52d5f05770be1381003259ff3211d85e64aba4724cc0819d38d19aec3d5286
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opensearch@sha256:85abfcfd241de4be31e3eb4ce9936732af743eb42b3d829b80835c2dca1173c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opensearch@sha256:38d99b26d2c6a1a523d8c9e7a461b7fca4439e5bc77da35f2558a5320f7f8a50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opensearch@sha256:74f5b160a8b9b1081a49911cb81d3ad4d46bc5baa603cf5cbcee068067fdd4fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opensearch@sha256:f29b38caa3fcf780da9bc7dab13db9b89e6906ab07e7ab903453c25e30e05606