Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.23, 8.19.23-debian, 8.19.23-debian13

Index digest:

sha256:591f655a5f616359a26101d3959d9973e840148b270e43069a7a97b3a9ffab63

Manifest digest:

sha256:8bf8ff49ce091f5ead65103136bf3e05537f1e152d8067ed3a930b69b7c2481e

Size

571.36 MB

Last pushed

2 days ago

Vulnerabilities

0
2
4
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:db7c173fd7b58379e47fceb2a999271bbd0fb0cec9d206bc1a3be01cfc567e34
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:4a0b7f23aaaf68def7974d106b1755a08ead56d0fd4670ca5c1d24f8c0d32ac3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:7b59fd8e04931e1ee998c3ed4d1a1e82dd34ebe7e67e3b25efd08a6013446f86
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:17925e15b4d879447243c5ec9c39b47f1b3126b84d261c0c96027e2e01fee950
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:161879b9dd1fdae4cb9b45c614ee754147bb6fd935185a7ebb3ebbca188f0b67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:bbbe27f233918cf1384011b5043b727766616e36b1f10b3f7b40373332601fcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:ffe67c0431d24d575237226c09718c5608484510432d2260559eaabd51977b84
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:1449e6d2066e2f3cc588149001628d8af23c2d8c1a3680d2c3bf19507ecdf7d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:ef3bfb5d8d3f3550cf245efb577e54ce32036953058c59bf1a98ecc7d3e08302
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:e84067f6f74aa2c612743fd5b39e539729c80041c9478c880a61011a665da2d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:3fc07d6af4b1e3c9b1e7a9f069317377141abb26c315281ce7e498f6179a8170
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:92f2c3e1dca0cc115fe3a109f594dfcdcb1f34ea75661b1ab022a6e277495639
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:0c0ea21fc56bb042acc1c758832674ba01284820889b48e54916fb085f70db3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:f524eb7917bce6dea6045cb44e96a4d05146633b53185a3a5dc19f197182b67e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:9e07fe79f643b3794fc0fdc44709b8e553053ff700e6e9e46b03537e82b29c6d