Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.21, 8.19.21-debian, 8.19.21-debian13

Index digest:

sha256:8da43f619827e576d2e4ecaaec9de9d3c3891b92183506c40a3fcf01cde0a5e5

Manifest digest:

sha256:ceb3f8167fd73623d598be1f281feac56927a1180cf053428cf82096eb3d0deb

Size

570.68 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:a75a703602346fd09b1a760952c9c43f902581d2c88a14f468cec6324204ec60
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:d80d56972749bf977bbbcc748dc5cc7bcd80903efbc90737f1129f07e5e3c20a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:b96fe8327746e8312c987697c53c6bf73b59a26dd5521e6b66fbd9b0bbc00026
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:8a0d79a08a69489213e473bdea99e0daf81c1624efc260fe085431b6c70ffb9f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:640c1e1fd52579d0fc2df66c41e7d31d1134de23f19c85314d869d9dd0f0ae11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:b978cfba191b5767b5911d6765ab05a9d399d057ed8493d325a3ca23ae1ced07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:582c0197beec94d50de8130907c2a244187f4d2163f9e01ffa4e2ce25c71c071
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:129cd09df63ee07b25f4b6a97a2a999727998ceb069eda053684325c8fb1dd1a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:3e663f32573f6f8162a82b52242fe7570b38a1511bfa5c1df693723160ce0326
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:d0c856c96b3f339a6db9bdf109eff6daf1aef416afa8cbe9bf2db765b6637131
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:1156baf417a37015b5978c33609c811b8abdd18c584942d1630b4dac2c5e0a44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:4aa91554d43e061eebd2e579dbc4db710593155fef80cb5bd6c3a841a50e708e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:5afef7ec60e604e6e8660d0bf11e2037ca57b3725dacca4a7b32578281e0bfd7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:9ad6cb817e393dbbe1a84dedb93364a4e671f1f946e848300790be9091bd9ac4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:edf898ff2e44ab1380f214277380701285716ca75d9996495a2ab32960fcddc0