Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.22-debian-fips, 8.19.22-debian13-fips, 8.19.22-fips

Index digest:

sha256:57c865c7639c95d467bbd9f4e4262e84660f350acf164e244482780bd2d65e2e

Manifest digest:

sha256:02d5ec262ec0ab0222d1a889189574adfb4f776250cdfaed7bd18c5358ddcb72

Size

581.04 MB

Last pushed

2 days ago

Vulnerabilities

0
5
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:2afd503b8cc14fecb7f1603e86784f7c61299f31642b5d378ea788b699e72db5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:ad8fbd68ff8f67f8fa3892cead3979b166d0e965785e901d4b5ea7611a8833a2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:c0af961c7f9528d8b6aadbd9d252abc7bdb9f1727443c7983e44a1bcbd4ccab6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:58ee22f4067e39601338b4d5b4c14713f39d42ee2b70d56f72ed66a646187ada
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:37df168298ccefa03dbb69b14d2085b758006c141f167489245f9b0f14a5913f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:d3ef791870ab364202bd6b2fc7b92e91345a68328bd6aec8ec7b4f327b02a85d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:f7f36bc9e4c1c02b5cf44e6a98219e8b81521437d8c71ef56565ef02256cc4b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:6c0e45b6df5c3f0d2aa396dd532eaa8f9e41fe0e500492a553ac5ccdf648fc5e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:3497add02f61ad98286969202e5b911d7775658a9ec4209e0e8dc4b81c3991e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:b3f4503d30ce706e01edfd14cac9eed114891cbf1e571abbe3ff30e54857928c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:5ed13e0e65c913bd4b6d866ec2148d5de6bb196401e2ac8ccae559caffb16d61
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:8c7af47bf788efbb25e278cf0bb3d1387d6a3fc4c5f27358cb7ac1e58f863489
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:6aebd52f98734a3e4cd28dce22ecf938fd9174ae8497db2092a10a5d442132f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:723ed8917709ec8e7c8ad9d3677e12549b313d89932e3d25572f9ee6483398fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:cf99578d9afdf52033bd65e4bf470d6432486532512fa5fe7e33ddb8acf9200e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:2c257e39e2092c37dd10f73915d0eec734e7c6fc2eaf3ce899c08d1a18250049
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:010c9e23fd4e4b0013f199812b59c310de9f9cf615ed8c48a57e56d0331b28c2