Sign inSign up
OpenSearch

dhi.io/opensearch

OpenSearch 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.8, 3.8-debian, 3.8-debian13, 3.8.0, 3.8.0-debian, 3.8.0-debian13

Index digest:

sha256:d525d1a19dad95a4f124a1fc9e6562f47630336685a2d61e9443987f5203395c

Manifest digest:

sha256:0a344543d288c264387d0f3b0ebfaa0e45513855f387f174ca509c988ccc8fdb

Size

1.74 GB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opensearch:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opensearch:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opensearch@sha256:a731c149fe259668ec6365f27c3a5c1b4580459cda9e237e71e099b2e702c040
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opensearch@sha256:b30b271f99793fb47f6129abc467681212e11e3ea8d0386d2dd87f24fa4602a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opensearch@sha256:d8066582150b0e9fd0b04cd1b1b031140c76195d59d896cecd07bfd936239639
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opensearch@sha256:5e77d6445f6373d251055579106bf7e526800b5092fc53031d98e54fface2e2b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opensearch@sha256:a244c7fa6b80dfd18600000f502081f9a106117f278e9aaae5103dfac05ff059
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opensearch@sha256:2d4ae85500a0ebfe26d4304ad85bb893678a63d84808ca86d71ad2bef0ee2953
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opensearch@sha256:1447bd63cf550509173ca51230d135792db6408531fe65365023b98103d4e120
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opensearch@sha256:697e08aaafd5b7a7fcc63e1decfc99f503a5e438ca82aea0ee22b8bffdebc910
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opensearch@sha256:83b0d8c3fcade6335dfd0af0e0ac1441d19173e24023c4ff6eff33218e83e119
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opensearch@sha256:93b847ef121e3cc9e930a89544e228d16deaf805e853e8f1e5a4e9ba0477f9cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opensearch@sha256:f73bdab383ef0abb60581133e8e7682522cb1319bfdfd843052206ee714f62e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opensearch@sha256:d0e5fc3c78f062671eee4d351da8337117859bf95224bd173439553eaf83ceaa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opensearch@sha256:c7b42da2417a630a444b1a42de41684c65e53851b431392005611056fd6ecd5c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opensearch@sha256:d74f31332f2263d48e86d681e40bf7b5bc2cd935a288bcb10e917fee1fdc54fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opensearch@sha256:2f94e7edccabfb34b583ff3bef189e0db98a269d09117cb743916deec0b67ef8