Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.23, 8.19.23-debian, 8.19.23-debian13

Index digest:

sha256:591f655a5f616359a26101d3959d9973e840148b270e43069a7a97b3a9ffab63

Manifest digest:

sha256:8bf8ff49ce091f5ead65103136bf3e05537f1e152d8067ed3a930b69b7c2481e

Size

571.36 MB

Last pushed

3 days ago

Vulnerabilities

0
2
4
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:db7c173fd7b58379e47fceb2a999271bbd0fb0cec9d206bc1a3be01cfc567e34
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:4a0b7f23aaaf68def7974d106b1755a08ead56d0fd4670ca5c1d24f8c0d32ac3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:7b59fd8e04931e1ee998c3ed4d1a1e82dd34ebe7e67e3b25efd08a6013446f86
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:e7e7c9322858143552c66cb6369405636cc561e34645f5da7c65178aff835d9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:7cc23b456d48122b4c591691d7ea26aad01279b7079329260a298bd5ac884bc8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:bbbe27f233918cf1384011b5043b727766616e36b1f10b3f7b40373332601fcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:ffe67c0431d24d575237226c09718c5608484510432d2260559eaabd51977b84
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:1449e6d2066e2f3cc588149001628d8af23c2d8c1a3680d2c3bf19507ecdf7d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:ef3bfb5d8d3f3550cf245efb577e54ce32036953058c59bf1a98ecc7d3e08302
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:e84067f6f74aa2c612743fd5b39e539729c80041c9478c880a61011a665da2d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:6be2cabd15f529a44086bc10e36e1f702af0e6ec128e08211c7306f2a155e6d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:d51f9bba79f91cd4bcc37e63e7321f56c75f89dc0d1baba532dd232629eae63e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:0c0ea21fc56bb042acc1c758832674ba01284820889b48e54916fb085f70db3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:f524eb7917bce6dea6045cb44e96a4d05146633b53185a3a5dc19f197182b67e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:894e52354b12effea4d829c0009329c76220644dd59aae5ca9e1f5553e0a55ed