Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.20, 8.19.20-debian, 8.19.20-debian13

Index digest:

sha256:0800ebfd24158ad23846dbd0a01de470288dac0a3de00ea74fb18fffab6d4af1

Manifest digest:

sha256:0401c2de7504d2be8367bb35ebaeddf8a3da37f7f9850fcd11ee21e50488894d

Size

570.68 MB

Last pushed

3 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:2ed8cf2d4922ae0d41e93f7a4058ad0d0717f83e66336c63b1d98d13cd49635a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:76cf47c8f0223ef374c6b084dbc8e43f9df7d20586c13f21872c8a4415d18e94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:facbbab4aea3b8ef87b2683ed1c49e14792d795abf1e75e4d0b789b27c866106
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:b70c535bcd97393da604fa1f4052ed9bd8bea9d5a2598044b712a10ba2431cdc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:e0f5138063a346345f7643266a8923f8a9291046059dbdcb17c6c86a02778ac4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:7749f670a1918ed26fcda2f4eb321e405d9b47e8741fd8213d058f823a07df83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:f7d40286f0054c4dd88569ae5a1762ccbe82a7fcbc47f52c68bde84ea842298a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:010560896e7a48cc0ea57f0841eccaa88f93a8991ffa84c5064c1d8f305951e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:e737cadf6b72a2ae8b888bd5c64b352e3c0bbadb098480fd526e2e0fcd615951
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:6dcf09c63c5a1d8baa6cf8b7a9b4de4f37da6bfc9d9f0a82615899fe84b5e273
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:466b18d68f98094180f3fd905ec0a1fbabb9428ff7a181091041d4babcdad12b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:0ea5d29c7cce5c417a090afe81f165e283e7b4d2496fad525d07aca99c9013b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:00db8ee0a47bcec4948b8a1bef590c0e95e2575bbfa94574bb41db2728c62f83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:0b3ddda4445466105ffe7a7bbac1db99443a51d87e6cdd58883383f1ecab3660
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:e5f7b21973da452c094bb193328f0d7ec9c2a289aef772ac980637e7c7d5ef06