Sign inSign up
Logstash

dhi.io/logstash

Logstash 9.4.x

CIS
linux/amd64
debian 13
Tags:

9.4, 9.4-debian, 9.4-debian13, 9.4.7, 9.4.7-debian, 9.4.7-debian13

Index digest:

sha256:406a2cc1c27fe5a15ae85bc36a1aef960f0e553aea5c8bf5a0c70c1a2c0c8dab

Manifest digest:

sha256:0e13d509f520d84e504a6541a7bcbabb8e67b38fb7ebde990666fe5199ebd15b

Size

413.74 MB

Last pushed

3 hours ago

Vulnerabilities

1
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/logstash:9.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/logstash:9.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/logstash@sha256:59bb335cfcf3681898698c6a5de380b61b92dba2918fbc5b259ad0034ffa52a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/logstash@sha256:37eb3ce0e6b9342f9cd8f00677425fe5f36e3d47dd9eab9233c0958a321a1c65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/logstash@sha256:ff26b183f9a7cb1ad95d7e116c433945bf5e9a02bd4cf08d92556da006c0f3fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/logstash@sha256:04fbf206dc66f179f2dd650d4360cbbea14d547ba1105288c9f4dc9356e4c257
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/logstash@sha256:496e3c4fb7311ad7eb4a50a57d7e3230113fcb8ce70405c448598724fc5a6ba4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/logstash@sha256:4309ab27b4265215f4d64834df282d6e031ba5ac79badfd24bc8e4e97acf7b7c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/logstash@sha256:82c765c95d06a73164b313f30e7ce0c7f4f11dd6300acbbc3a78a2e6f5eb6f51
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/logstash@sha256:b01f7f887cd67591a216db2dc727e1fb2a406d84196c286831aa3555e035c490
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/logstash@sha256:87ab0b6a62b4d11b8f0f36a542d539baba87780a3c962ccf2d1a4b54abfe7c06
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/logstash@sha256:a35c20d806c5d17d442d91e103c9d568d3514acce018a8c1d45879bff8db4913
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/logstash@sha256:43056852b84eab32b88089170ee8817a620b86ffe92e25f8429424900588602c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/logstash@sha256:002b8330883ab0ead6c7326591d98d539ba4e6f9cea1696ac9bf829960fb50e2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/logstash@sha256:caac1771b93d3487112dcd71a4ed13e92450a2a639517e326a3d143b47cd0727
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/logstash@sha256:e09296c9f4ac75e345033eb4d4f7d89dcd749f9b5c20f5202b1fc80a8af67d97
SPDX SBOMhttps://spdx.dev/Documentdhi.io/logstash@sha256:4daa512e478de623ca1327c89b4f58de755f3e2940aa0113f76dd6df467899d4