Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.21, 8.19.21-debian, 8.19.21-debian13

Index digest:

sha256:405efcc01755318d1841249564e2a16884036fffe18504cf156e5233c9e8e436

Manifest digest:

sha256:f25d8cbaf85003f473823a0ffacb21b7993288bc062bb0c5e2817fb420d3140b

Size

570.68 MB

Last pushed

58 minutes ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:bae2e1667818bb38bd5cf6f01f66d984940b4327458c2027b8981481ea754cc8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:e385880e9b1fba57f5fbf37ed6c374e23e91f18cbe29ce0007d676459dcc0a8c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:1de17413b141cb3ef49682d185a014502f36712f25f18f876edd31e90afb411c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:815388f540a9cc66c9fca256c11152c6baeef022e1450d1f5cc2bf075a09e7e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:fd165332cad854cfcf0c5b1c22af6b60e06c1bafc627bece5148e7e312a89338
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:172bf1017e5b507307479f3cfe56915bc90a4b38054070ba9be43f17eb11e406
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:1cdd061a7863b24abdc0b8b13858d157b7146120383f8f24b8a762e8a2e535f8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:cad711427f79e2058290b061697f5f134a990780664551d73e4d460feca70f1b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:dc48efb48d247a37432d49d73f9c6f346db863bfde4d6a67834b8b19047f4c50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:14c3a5bfb9fecd24203983507020d3b79860ea43ac4c7cc7bc507b2087c1b9cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:df46a96a6801990f1313db33f2f7385f0bd96a6f6f98c8469fd0f028829d22e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:9a33bdcdd975477dc7c141d1f1930417c9ca5584c8ac3a5333c49a3972153179
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:ea44a27e03b01e14b9a4173aa4a70ebe6f7093f645a81c5cbed05745c6a8bb68
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:a4c461e30db3ab51c3b37a261aeccfa862f381be2854f28239632a81dc4279f9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:73589a782f85978185f2013e7fba0d4e4c8c9da89b63d4e4852547cb3c8b3800