Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.21-debian-fips, 8.19.21-debian13-fips, 8.19.21-fips

Index digest:

sha256:3dc697279769dd4da4ad8f46f98b95841af9ea05110fca8dcd75315605d4f6bc

Manifest digest:

sha256:1f9458ad5d4c9592ff99afa3da3a27aa647e5167422eb4f4c110f090f70598d6

Size

581.11 MB

Last pushed

7 hours ago

Vulnerabilities

1
3
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:02605f03164824976351858969decde708fa64b4f5a4d98d617b7f5d91cd61d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:f88d2503bf47a9700db8a36ede7ec1d066991635af5e215aedf8f176b71d0ed0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:e9227a1c455c14c13904a80a5f0247bb34cda8e5be2e67fbe499b08eb498540b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:9a1b49c7d9d0dbbf475220d8db47a0849b7dd5e7bc24d1acf45603cf2729ad1e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:2522bb0e764bb56abb5ada976fccb1f5c791d8f124639f1c58d5764763295398
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:1cf5bccc2402382623410adc384954dbedaa90e252baa17da131f5a3903f53c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:525b59a9e9044145669c7a2d6a0e84c9c9a864d8a12263c552829627f6395762
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:72e9051508ffcc91a2ecbf246c57dafabe95770d9da8b370461ade811d778bc1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:d9a38751211b0eeccf36f6b83eb029c818c757e1198c069dbb2a0a5ab83a8881
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:8a9923893ae5712d1a07d5b20d8fd83cb842dc00fa8ac8ac20b917ae0585199d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:63d347c2a966d666cc536d14193d5fef43090c12aa20c6f6ee533d19111675df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:728c3191108cf858ed7f3b6a6aec8b03898fd0764d0b014340ed1d3fa1890603
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:ace2dea25fe88ca88252380b98f4b9bcae451d2dc70c20abfe84071c388ff6d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:1414f95847626bcf4e59ed0d10f26f03eda031b92943c49c21430b0e89eee2cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:51b17c9ae0df4575132ccbef9fbb19821c4b8159fd50e0dcb0b4f40017df1778
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:732b4e413fd7d27d71d69bd475ddc2925792eb8037c5fed8318acc669ad3d7ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:ebef9ac5f9034c84bbf0a5fb8f201c2b14425cb5a39e4716da5ab3c9942ede57