Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.21, 8.19.21-debian, 8.19.21-debian13

Index digest:

sha256:bf1dc422c93c6a51d4eb68358f811bac30809f7f930de5b190f3a04141946b2c

Manifest digest:

sha256:7c323a977074364189a0c41d2e4b31d55665c50ba9e61ac08f93266204b7d3a5

Size

570.68 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
3
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:46872345f7e6801007ad9b42ddd14d0ff7bf8c405515758f3ae1e3b72d7c28be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:4dfb03ee5636cbe9583bf35b7253989519fc01bdf9c1494f52a829b996264d10
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:23d7f9a5d6760bed90e6455d90faf2f374353d93c3488e76a26e610add70dc5d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:1075e3ca096bc2214c488362ddf3c43478e2532fcf047b9ebc2c9593f919f5c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:9ba34f19cfb9eb577b98da8895ec87d141fadb16c5ca0a3c031b9f399486b0c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:e4ec607d77c761bd994ff03df449a3b6c305f5d4a0c91d219c7b79f10120ab40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:5c246fee6c5bf37bba09db4673a159f405a8d36b55dc5a9b5927f2760d34d2b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:d8a1979c5c7bb8a151505603ad07c489396bf491c1eac51af2eb8186acecf45f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:b427ef6e7243c66f9ee05655b9a3be6636dc8329ba3c247f61fc1999348b81c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:80395948e8e4b22d13d0fe4bc669e5679a510f1411105a13a7050b2b55815c2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:8dba9c1a94094676a4042c0ae0f2180bd8062a8dd45e5c191033c927de2fc703
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:2dd2034ca81756d4b99174f2252ce7d0af10ae3455bf3135475de37da50e523f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:d7ba8f0b815e3dbe96733cf66d2540df0c699a1dc943045c7146e68223004ed9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:70e7d89cb18d25100b7424ad00a610aa54605c4d2a7094258abb0a1f08b70e6c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:9bc967177460a6dc76f6316fddf74fc79d772d8f9bc2789d0bfbcb4b890d4c37