Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.22, 8.19.22-debian, 8.19.22-debian13

Index digest:

sha256:ff7f34107cdd0a057701b4a6c86fc1dc6bfa2a8961a5e4ad26d43f9d61b2049d

Manifest digest:

sha256:741c112dc2bb4ab67f8c8e836568ee657e7646d0910b330d98bd7d6f3e27e48a

Size

571.32 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:3aad9584ac0cec0e082de13d2fc09eeb9bb4e2f59a3ee7b9f50c0f6e48f0e35f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:ea5488e0d6984d05240122cc0f57365e1b5be53350e128af5f4a23a0513da729
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:ecf25385215e991af8d0bbda0f1db15a478fbd75b5a0667ef4ccc05b90ba0ec3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:8f88c7ed0c4581c8e9e72c384107e0a54149af7bc7fa1e0d048f9e1baf17c334
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:1e6e0775b22f8d853742f07d39490fa61eeb11b834f362229139b0d6fb897322
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:2d4b1a80e9ccc379496b36b24244da4a97745f7eb42027a4ce292020ef8b8451
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:c22e13746b2922f32656ead2f0849d663cd6fb1c80ed850c8c04432aad2aed7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:2b6d40df14ac0bd5180c3a27a586926b6c7de7f8808821cb90e20c15436032b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:8c5aede6022ba645c5b462b85c30c41557dfe7d68a1128aaa67659760e4a38d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:593a545fcef7b90ee53059ea610fd59c48d74af908b8f8b73bd604b51f4229d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:36eefbcf3c9862c087c251d1f7e3c02526771a2aa6f8b0338873ec3f4fb5097a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:6df879ec3caa68f3d10bbbc23c5b857cf67b618ce3abc9e842de86168e93063f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:92b296bc0a9bac62aead7f77b37191310159cad80007b1b053eda8f3b2bbf6e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:712ccadc553240aa5cbede8611d3fe65f545562712818e20c677bc96cc187bf6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:20e847aefc63af4042515aa44cef672b56b79ec4f3d9d1ffc671008939a3a309