Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.21-debian-fips, 8.19.21-debian13-fips, 8.19.21-fips

Index digest:

sha256:769945aaf361845d5343e890d036932c201cec363920ca05b9d7d0caa6c718e5

Manifest digest:

sha256:e8639c0362a2b0ae0c94a200155d0293a514f46924f9abac99656cbcdef9f212

Size

581.11 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:b4e3c5b1cdb21e8128a4b76be2336537463939b310cab278e6fa93b0f166315f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:7ad3df0b7e1b4d4b97fd33f7f6c3115bf9bcf7cf9c4869062c8fcc7bcd5626fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:7f6e9c8f471ba5e5ebcfe31af91556d30783ffcc56c1a52b7bdcaabb3a82b887
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:edeb0ed604ce814ad641eebd8632b87e9f767f3b23252051785f99934119a1ea
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:bd059e720c915d8747391f206e60a56ba1f09a9a6778ed1b3fd11626a4d75521
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:0ba99dc2839451c3094117d3c0ea72a322f1a50cb71666df5a0cab24a716abc9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:9639a4cebf720f258709d403a266359dbcf620282cbe5f10766443090a051c97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:a3d36486ad68bf66e0b1607f6a0e11e367ac5d64ec941c30cc8f073227f40bb4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:3b913f19940210ab6884e5d40e7348a6ed41fbfdbc64e43122eb986cd53d65e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:fce11a2500cef7275631d9623b601543276f257d599bd719e130edc94357b0b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:f19e62439a11bc346e69df7214f3d3c9d629ca81f397f57c81f14f9bbbd0b24f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:6a0c52d46a7d5545d366db2afe800d5fd2e53d8dadc2df5e6bca94e9164a8fac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:925eaf4ddf05209c2ce2ffda4f32546d5c9430346f42c28811431adba13446ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:38f19364aa0ecfd5eb752f638e8030ce273cd51f7ce3246a4d7328143f6b0801
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:5162ed4e4529ad0651c2c239f50faa15dc28dd5b2838eeb01f6222898f063649
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:f0fb8e6f7e2f9972e50eca9d673a8dddacf28a6a475ce6c381f4dd93b5afee93
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:0fc8fc8417a5020234cdf79de7241b3f7dc60aa7e545fcdea52eb4f33d16d26a