Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.20-debian-fips, 8.19.20-debian13-fips, 8.19.20-fips

Index digest:

sha256:118a5f511f75c1b80c39bf35c12ecaed8a76a54f3c53296b7b8b03984bcb3ee4

Manifest digest:

sha256:975bb478eb2be0751853838a3f592aa2f174ee7b5e03bdaa0c1bc6eaec0e6250

Size

581.13 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:cd837d74240321e09a81595085db097c99cd4535118221b7d80a2f20999f3fd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:84b2cc9a035c4239a48746be135be4f5f267631750eb554f01a9504093e04d77
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:147dbca9a8ace474058c1f087065911968c3cd7469b73efbd61a6ecef9328984
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:065784daf68b6378483051db8de39192039b736ffadb631f7407c49e2dababcb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:2605d7a6794773b488d8495ffb1006ced67622ad10be5617a9d73e0224f0806e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:73be7207d6b76b30377651fbd8c3c087a9db5ffecc5f42641e5b07963910cb23
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:7e43547dbdcf0958d0b82f9a3ca40e588377dee697450ac6d0c00749e70b60ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:9120a41c39d51e65826d106cb01281c88898aa63944d42579194b294f773e530
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:3173a42486bddb2d92f51c8bad9f9604d622e951b9acbfd5c71f0e5be6fa1a61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:8de8e93170f9740ade0948ebee69f1c86cdb544d57ae243098a4e2ffc857b467
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:6ac5c8510ad892184eb7eef979ebc32112bfdf1396c638d32e25644658c5fb55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:fb3fb0ab85905faf1c74784fd132c2fc9483f81b0a4e3d5e92bde6134744a812
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:629b2c414a195b9a5d9edd84593b1993a72d6d5eecaaafaff644d41dbfb215b8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:6f4e9b8ce1f930de045b7906ed9b72bfa29fe6bfb96edd4b789ecdc9fb504f4b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:01cecb11a3822ff03eaefcda0b33564b3f9ba9f9f201d43af9f4d24315643e9f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:378b7530f816517f72fc99e68ad22c0dbcca68347d8cba2b3bb938526a0f9a55
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:052d185b2aea2406c351777a84d2b6ce2aa1d13a00c8ebc21a9d6b7dfccd68e8