Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.21-debian-fips, 8.19.21-debian13-fips, 8.19.21-fips

Index digest:

sha256:90711b901fa9881c2988eec68b0b444a4db1d9a4007a1388d93376c08e59a8a6

Manifest digest:

sha256:37d29df6fb8a9640e91b6d334ea1d53ec6a01a3e7a9de0067a9e705090a760d4

Size

581.11 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:ff001ed32aaf13f3ceab20d217b20beaa4fb7875ec750840d43923f2a5006196
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:5c0d5263f05a5d228e7dc08d5968d83f5a014a75c821b539b449c5403cdcd502
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:8e9336228ceb6f15566abad16aadbeb9781bb20418108717f8f655ebd9fe1ab5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:b364868c054fbc63f5c8a4177b6370d758416a9b80b492a320d4ccc80e9cb330
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:13ac410ed167f2b03af7176f114da8a13621f3a059863b0a1352a25d21c69381
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:175c1f2a025a466adf8ea3bf6e16c52b6d9292ac02e9c998d94015c7eceec178
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:8828645054d814231d9390bb03c7bafbdfd5bc10795678e9cccb4c0463da4ff5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:6ad56cb4c8d1abe39e18c38e84f6ca247d2d2583f2dcc17ec963c4c2e2e45a32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:bb8788e9df2991380baa06048eb075ece47f32dd562a657b48eb113b2fd4b083
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:992bb2e06bd3cd3768889d6d8d5ee266a7eea83634357881dccb0f5ccbf03983
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:27ca6648b31960b27c666ae5ef2e712d167ffb5e894afd34d9761019f7b46cc8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:6846e6f96a2da202801b014f118d068ca47aa26a49ff7407bc8f0b1f97aa8919
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:fea92dfa130984a54448fd2c443eaa5c42fa044cd6433ef59964d19b4722c3c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:c097c11e9d5bc802e0c7f6cf1a5a4f934bed8256f67e72741f42aee7f24e7eb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:70860ff542932f208d1d970412f56422d83dd21a534f131ac183a5f30e0eb0a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:0fdd9439c22a3008a0978725c4dde78e4043a108cee4deaf8bf5eede76ab58b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:205fd1630514e7787ce98b0799455c8dba8063c2139f21b8977a08cf199d3560