Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 9.5.x

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.5, 9.5-debian, 9.5-debian13, 9.5.3, 9.5.3-debian, 9.5.3-debian13

Index digest:

sha256:6f13ee0971f44f6dd779b06453a3a0ea8f89a30a597561e619ed1b658127abab

Manifest digest:

sha256:f420022bdbb879e3e483060c36d032d45b1c24176a752c2447b785989ff7c69c

Size

714.02 MB

Last pushed

9 hours ago

Vulnerabilities

1
5
11
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:3ab0311e6f04bc4db23451c31a72ee756aaa119fca27403e6194cba6bc757025
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:51e3652ba2e9ea0f6892eee03464c67098bd2f3710b75d2a22492b57536b3488
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:5839f133a88af84baa627995a14c34ee843f88cf80d58418d4a43c6a9439339a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:076f29b055c484157904c4fed9b5019945e65397c68d8d04f3e380b67c7d941e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:ee644fb9753015bdf45ae9766a1fc4bc45521ca5c5f8bbe4661960431412629f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:58497644f5c71b7e293058f1ba221d25d53a0577f933d4527200909827080808
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:c3ef03471b28b6109b404e51cbd2374a36c6c301fc97d06c4204b53225dad6a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:7a6e889e4fd2041e47432c21d1110fbd2e7b5e340330a0e5fdb865e6b4cba33c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:424b4a97469aeafe0c18cc95d9d00d74f5a14b9d5068d6f9889406eb27993230
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:32c9be089d1c12339926b1c016333f96d26b4762b6369ca57ae29f5313151d40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:d094918e5d416a5002fa12bd0e0eb5d8b64323f7140f82803b69adaba1c61a14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:106b16ea0d608894ca7e00b172c4d9cd5f2d37b155de09e267cb2b06a01a1918
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:5618c4c579e56f0ad83e595365211b7b93c64ec75d315504c6434cc885f63ac8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:1ebd7cf91923e009ff6122e1865685e48497736652779801b66fcec4a0740c02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:67cd84cf14ab6d2073bb22f9810310b8ca4ef16123074a26bf1327cbb0878211