Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.21, 8.19.21-debian, 8.19.21-debian13

Index digest:

sha256:cc43cba1fbdf1baeeb9805950f8f954c97ff3fad650fe882e625fc0acb993755

Manifest digest:

sha256:971c83f65749901edd5edd3d4ad8b71ddb62bb9c9be2d7c0d7bf371c10b7b03e

Size

570.68 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:9f715856e85bd32f8e2a33a8b5c796e0e64394bb572be96282e14918d1d2876f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:0eb78bea05d9c4160802bb833959a417fec2cb755510e6c19025100993968db0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:40e07fa04be92ba99111671c929e149f48908cd5084e2ebad43fe16408051bff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:4410710b8216c0d03953594abf45b13cbff4665cf7d45b96a52dd05c0903da54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:d179d99f5ae9cb7d651a2bbbd40433f5c59c5445f1733db61889f019a97a046a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:819a7f39c5908759ad333872174a989c24cda7abb8af3e0e69779e3e110b22b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:5cb7fc144a44bb6425738a431996744fc408849360a86e08231f21d1c48cfa6c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:d9879b8839de730902721c23647590f40ba759399d9aecb3d6316333ebb44d23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:c80a49a5a870b28db157957ff6a69283016f95c40e4d573ddc2ef7cf55c8ec82
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:ecc056cf1e84b10d2fcd5aab7ea94a8c11bd7c19dcd5da02bce64272d30ee5dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:1d439e625e3c06dedfd0440db138ec9f8cfa68f0fb1b12d41270addaf8b68e61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:259fe4a2e12c736c7705335d292fa5c2a93e1dfb5173d7dcd3e9ab14e447ff7d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:65e5641f74d0b4fdc838f8ec58f2c7fa268358f8de39f7a71436dfddb981e2a1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:41a1119fdff51f6c0ced1a99ceefcbb1603d6528918dc054f8a7a464ba4dc22b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:ec8a79663fbdbdfa4cdb7d8a9f26c78dd6057ef6663f55885e26446c939916d3