Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 9.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.5-debian-fips, 9.5-debian13-fips, 9.5-fips, 9.5.3-debian-fips, 9.5.3-debian13-fips, 9.5.3-fips

Index digest:

sha256:83660a5d570dfed16692a5d08e47b44d90556ae3e98c46f853805270c022fd92

Manifest digest:

sha256:12c91976fb87ce1508e6894dffca0b60b837d839b36baf76f9253ff980a35193

Size

724.48 MB

Last pushed

10 hours ago

Vulnerabilities

2
8
11
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:687832b63475cadb71601a3e0a95ce66247790faab7c12c3f8c2917649fd8ee2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:3e5bb216a907c1fd6aba85043cadec85c7a87a3e1b412320f36b5f78db026243
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:3856977da274061dad85bc04d874d24a0131e42523d3956e2dfa3aed4324c8cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:b16dfdcb54770a8b0064d06440d1828d2042f4a1352e639287ca1a7aa22d6d56
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:ce30e2f19d91b4f9b69d3599deee2e3a74c4af850860683b206ea59218ad51ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:7672ec2522d08f9b870710379ff50bd73ff3867ae9e793c75eda25825a53601c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:939f595756339ecd437043ef0bd4643a67c16fc567c0b98d2d20a5477c7e15dc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:00d471c0836c4ff7cfc038c0de86be84e5837746a808aaf848695c97e97e0b3e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:6c04e5afd106f983cb8ef9d4b6188efd811a8b7a9b3684c0a42fc3676677daca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:aaef8e556d9620b295cfbd1c773a1e9cd4b1fdff60a3dfd0dc1b239effb2708f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:3d3f32314c08a9518a82f0a98f36661e9d8a1ed8530ab44d4647a32d921f96e0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:2e56ec0575d41360f03cc7e27bcb4667562b3a2ba1576d0ae985c291df825cff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:566e6d3c80e00da06d34ae9f57341c244f4adda1d6df1a3520619161cee52577
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:ba86bf4d17a842227ecaea2d153ba3207dbd36b7d597767201b6c5f1793fa2d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:a6735b28ce6694e87a1b6130bae6b0f1dca12f31a6d52c343c22af66d934b86a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:2e9b617d7d23e6e1229032a52737fdb35d7c93202a18cca02af0867b374cf9ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:c5491ed53293f3b1e0e8ce25ad8ab4e11f8cb7068a30ea6cb81ead9ae896aec8