Sign inSign up
OpenSearch

dhi.io/opensearch

OpenSearch 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.8-debian-fips, 3.8-debian13-fips, 3.8-fips, 3.8.0-debian-fips, 3.8.0-debian13-fips, 3.8.0-fips

Index digest:

sha256:3918ba547773c8d36332de8fd145714aa721cc9673b38f1f2dc764b43181b831

Manifest digest:

sha256:70488e5ba83458493aa1cc27d3eb9c4352444ce6252f67685c86d224d711829f

Size

917.29 MB

Last pushed

4 hours ago

Vulnerabilities

1
3
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opensearch:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opensearch:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opensearch@sha256:0bf36df141f731b8b70fe5264afa75e18298fc923327941761b2c1b5cbf75d3a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opensearch@sha256:142392eed3af32271d68dd706509cbfe6483d480d12d0efa6d651084a6e0b97b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opensearch@sha256:e857a492bc15a4b31042038046dd7faeb40a86952a50d9627ae05a204fc90707
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opensearch@sha256:eeb592b3da991408e50abf1288bce71384e7546f5b06ac24b91d2d4ce607481a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opensearch@sha256:bdc87e839b4c60bba3b557f3697ca0831a9df921ee8dd2aa5f792c36a43d7bfc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opensearch@sha256:a90b477eef9401b4f85d87ccc0d4bd788e44af3f75f5f6857f0d1c8b45d4f4af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opensearch@sha256:90acc2db1917a7399f5a15b40cfefac0e1f950085919a7162f0d18d8840dc3da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opensearch@sha256:93ca9c86215b69201b823e73c328654ec32ed794fce102466beff0aaaf0ab23f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opensearch@sha256:c7400412a282f884752018cf6ede39b2d94ea54039077d461ecee2e951101785
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opensearch@sha256:ff6c35460d6f7e28963c120da711db5d255bf1b18126ef60d05d3ed2f06eddf7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opensearch@sha256:72015d0ad4a60da1be634752de63a722cf35d4fac47d30e7202589b82e7bc41a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opensearch@sha256:e4eea94ac7ae1ff6359725fdc73a21f736c6453093b48f820bb2c7e13f046e30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opensearch@sha256:afd2317275dca614740e211ad045585cfa94b419d825dca5bf1046ced65574d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opensearch@sha256:0de92aa85bd9fbb6d8028b01b612c54ab2af81693f565aa72d1a164d96237f71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opensearch@sha256:90b0b78ebd6b154eb62d670cc7b718ca5019d84005cdb75e9c9d6794624cef55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opensearch@sha256:b8992e91f49713d32ddbd955e589d82b97b78e6ad1f85b121e32a1a289087b24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opensearch@sha256:f0b56301e517a0e9ca8c8b48ad56e623bb37350b237d25a340c83678581ac250