Sign inSign up
Logstash

dhi.io/logstash

Logstash 9.4.x

CIS
linux/amd64
debian 13
Tags:

9.4, 9.4-debian, 9.4-debian13, 9.4.7, 9.4.7-debian, 9.4.7-debian13

Index digest:

sha256:2a2eaa42051c3518857de5a90f9fe0a4909aedf08e2abfcad9956cf0069bb25d

Manifest digest:

sha256:59bc380ef1104e3be1317e6909ce3678169a7292fd9b0c5f810ffadd66adf24f

Size

413.75 MB

Last pushed

18 hours ago

Vulnerabilities

1
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/logstash:9.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/logstash:9.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/logstash@sha256:44497920ffb1c4d4a81217162d627780d29da003a2df5a048f8408bdb2df9543
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/logstash@sha256:2a6ce5d51d672474cdc0255d0701d0a68b2d05ea7ed09e2f0c558ae8311c382c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/logstash@sha256:2c6e4128999b42b6be0ea2c947eb604a214489d6983e38e227be5f5b0e5faa13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/logstash@sha256:2efde63218921c4e1867375a601ef96d72c096edfe196889fdeb8d4a62a8037e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/logstash@sha256:714350bc872fa7407ddb23cc9f59ca2355eed0c87febd27378ed13d58eec51c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/logstash@sha256:a604dc52c7aef6a32acdc83565c8bd2d3b14d8d8a0a7ebb3acf85edb54091b3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/logstash@sha256:021d30e4e6fb7a0595196ac5dd8fc2ffe816636bda611e1ad1231685cd1f0832
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/logstash@sha256:5a0316173c20f2348d4083e264a34d29b59bb424b2f7f823693ab6bc059c9839
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/logstash@sha256:71c8fd04b14694f8ddf1fe7df67edf3e5a6ed9ebde869b02a82cf39c30395e9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/logstash@sha256:8afd84d59a3489b03d29e760fdda33bc8db44bd55f437578ff9ebd247347436d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/logstash@sha256:a8f1edd8c50f343edd6d745ba5795eaa9368f09a13932f7d5ef70bd2a2ff73ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/logstash@sha256:9dadebff1aacaeb152333da2637cc3cc2c4ee282584ee672fee5bf58f07889a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/logstash@sha256:bca51740b9b9860749882b8277bf67202919a760110094ddd905586f228367c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/logstash@sha256:d98df2f397a6f8baf2548dde5c586bc8c17125fa8634294f5a44d7de7a17b21f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/logstash@sha256:3405788ad2713bb779adec48c2a792f75863a811520c6a4fe2859f11531ba895