Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.22, 8.19.22-debian, 8.19.22-debian13

Index digest:

sha256:02b37855fa147888e1d6dd63c0d1099bd8588b246cfed9d59241a1b2d774a7e9

Manifest digest:

sha256:d0a31fa62565f77ed6444798148039a54b31cbcad0643529c5d84302f661b0dd

Size

571.32 MB

Last pushed

2 days ago

Vulnerabilities

0
5
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:a1e566d0fb9dd70004707f01074126b47d200b61a6c76fe0e021e1bb5def9036
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:a11be8b2a8ca9e20338e1452695d01238596c45905a69d0f9bf0c46254050759
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:f0616611f91950e391f8f58310b85f199392cf1f0bc263e9211ea42af3f484c5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:7baec4b97ec92b1eb7b9d066eac638437751f88ab25ea16af8b12edffcad8a6a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:65be245c460cb355b15deb6b2e71aef9a94a71eb616c7f57967bae4740d9b242
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:dda80b13779e300ba7288715e12e0faeee78cf178f0852265fdfdf912038c113
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:70fc1cc2071fa118f54103381dff818d3b5b7a8532613318dcf052b445e20472
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:3403d9c5037e9029236ae21f8fe29741997f46586956560f554db89e6a2e1723
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:3b1cf51bbffd65fb1e84704fcee5aaf7569d11bf03e49edc10053aae968e129f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:7b2a67315cb16bc2e1d43cf15c23d0d4baf210668c7b966211f0a70862980375
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:2b1ebada5dcbb6b13bbea65a48f709224d6adb182a8bbb9d89754643e41352ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:8d9fde64f148c67f3631f494748013daacd6f4e1dbb5734b38e1124c9880a926
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:6607ab283f8c3a249fe15c54747e1145ceb61de834d0b2b48ed3d7b1087d9a2e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:02d2c8b144aa24860b0199fcbfa107101d963bc96009688a1adbecb6a125318a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:bfa1beba9cf880b87f4ffb5b049abe422cb9383d91ac478a120ab0413a697c0e