Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.23-debian-fips, 8.19.23-debian13-fips, 8.19.23-fips

Index digest:

sha256:c348c115782929921a12c739ba4516948b05355eee9a0040c56ca3868ecbd31e

Manifest digest:

sha256:18249ac3bab9770c206d02520b5411928c61f45a54049c9c34a95eeef4012b0f

Size

581.09 MB

Last pushed

3 days ago

Vulnerabilities

0
2
4
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:1a28526f1910e193913dc60f81746a3068d72c1640ee2e56effc365debdd308d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:f65dc4b435a5e0027588ad773c195d0b3de5ce4d3ea6be36c05d766880ef5b94
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:e800c37540c64c9822255b35c501645c59cd982a360f02662892f7ff038fe5f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:2d7694c693cf67ea96919da70ad4e7e7b3f5c61f1b34d67246f0c82779783ad3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:d0de4578dd5cf94dbaa7a7e65a105a3e548d8e9d02c23a7427a9a73c2f90f4f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:16a88afbe0b8404372e7ed729970b70e27336a176c8076e0b1b9e42558180d2c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:0451aa9cb457c9149a24cfb1c61034bd168254bbb24c15ae1deba1f5b86d9ca0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:b23fff48fa169092df0ed21ebfb87457fc3fb74e71308b33f49e41e3a78c1f45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:590b6b2b1dfbfcab0269359e23bfaa4a8fe71086dbb901ea57e972d5758a57cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:266bb99b28f1f178503392f2bad9240e6fcd29fad5a1142cb3d4afa309a5514a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:955e66cc699ced37c83e94687a01c54ff7f5bc525571ba705287da7b5259ae72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:082c2ff0967bf3f185198409dad8210ab7b26798998e6d468f2471333d7dee90
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:0cab1422e8155be63e7e04fa0655a5b3a9f8784883e94bd25bd276a6cfcd6d09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:ebaec89cf21e56fdbf6cb0e8a72f90b4dfd2d14e9595ef0b4a4dff1a0c101b3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:82aa678e68c4e004939fa30f8411f545143bcf724feb57db357e8046bf67d0ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:288a5261be16f1a2ebb093bd1e18ba8108104492af2f2882d84e876797123904