Sign inSign up
Logstash

dhi.io/logstash

Logstash 9.4.x (compat)

CIS
linux/amd64
debian 13
Tags:

9.4-compat, 9.4-debian-compat, 9.4-debian13-compat, 9.4.7-compat, 9.4.7-debian-compat, 9.4.7-debian13-compat

Index digest:

sha256:0aaba03a49fde714150a585fd6c33d0668ddfd442f27b569eb19f94d1d199415

Manifest digest:

sha256:8d3d7af7cb8cc5b7261c282f2caf8abdf4a8d6beb7c93153801c909750b88745

Size

413.76 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/logstash:9.4-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/logstash:9.4-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/logstash@sha256:19d37b61c01a0d4372ffd4172c0fe231626be7750666bc132be636bdfb90a111
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/logstash@sha256:04f60a2c00d2e287d47569060ee78f9b6a6253c026483f0127b9fab8e86a2a29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/logstash@sha256:4c2c63a51bffc0a1b36036a0270ec25e2444e50c5441f0d90d51cd9f5cf80a36
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/logstash@sha256:73a6a3223eb613c016715613f693266ee519b89ca229207ce7bd7e960d15f257
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/logstash@sha256:fe6c3e792b4a268c3a79db8404b188392ef3af339d093e1d71ad47a1f0cdcf1b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/logstash@sha256:23e206e9ed4a1bd005fa4321e13af7366b71c69955a51432c65740370f3b6458
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/logstash@sha256:04ea6ebd38ef423ed58fd4d6d90ed7032318e7fa72e915505e45d5b6136326dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/logstash@sha256:e0e585a0ff354aa4f57be62a9d91c53fb5e2ca96d6c6e7f6161cf859b453b22b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/logstash@sha256:86d63dc0cf503ee73652d42f518653610467cf60bb95d1a0463b931274807aa2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/logstash@sha256:fbc0a90d276ee4ca1f38ff6817b805d012bc4592252e0cf57ef198a9a32a5df3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/logstash@sha256:b206c3fc7265a8543661887e2c640754e8fd86ec8a0beaee39f67579b54c9040
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/logstash@sha256:fa74fb049a97940a3f44eea983c97903fa1ce83f9139e77eaba522130f89de4a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/logstash@sha256:a372436b0b7338c718baae61a4b1d164e9c4b72e70b3d45548b083531d887246
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/logstash@sha256:672406ce92d4f0a945c8b0934d44d819d85cb5ddf257399776bcb4b3b4a04624
SPDX SBOMhttps://spdx.dev/Documentdhi.io/logstash@sha256:4b3b291dbf42f06ebfa38d0792835d70e001d29c0322b43800247bbcdc855180