Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.19, 8.19-debian, 8.19-debian13, 8.19.20, 8.19.20-debian, 8.19.20-debian13

Index digest:

sha256:0800ebfd24158ad23846dbd0a01de470288dac0a3de00ea74fb18fffab6d4af1

Manifest digest:

sha256:0401c2de7504d2be8367bb35ebaeddf8a3da37f7f9850fcd11ee21e50488894d

Size

570.68 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:2ed8cf2d4922ae0d41e93f7a4058ad0d0717f83e66336c63b1d98d13cd49635a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:76cf47c8f0223ef374c6b084dbc8e43f9df7d20586c13f21872c8a4415d18e94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:facbbab4aea3b8ef87b2683ed1c49e14792d795abf1e75e4d0b789b27c866106
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:27a61fedd854db4a338ad1a2a6ce1e561fefc3eb4c7a75ea7cfda8a1d2bdd303
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:7bac26846d25f224312bfbe3529a8cf3ea8b9d669c3bcd42a80369eae8964d59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:7749f670a1918ed26fcda2f4eb321e405d9b47e8741fd8213d058f823a07df83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:f7d40286f0054c4dd88569ae5a1762ccbe82a7fcbc47f52c68bde84ea842298a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:010560896e7a48cc0ea57f0841eccaa88f93a8991ffa84c5064c1d8f305951e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:e737cadf6b72a2ae8b888bd5c64b352e3c0bbadb098480fd526e2e0fcd615951
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:6dcf09c63c5a1d8baa6cf8b7a9b4de4f37da6bfc9d9f0a82615899fe84b5e273
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:22a4dc51803d4a2563037831a262830dfb02d990af2f500338f49ea331664ffb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:0ea5d29c7cce5c417a090afe81f165e283e7b4d2496fad525d07aca99c9013b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:00db8ee0a47bcec4948b8a1bef590c0e95e2575bbfa94574bb41db2728c62f83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:0b3ddda4445466105ffe7a7bbac1db99443a51d87e6cdd58883383f1ecab3660
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:e5f7b21973da452c094bb193328f0d7ec9c2a289aef772ac980637e7c7d5ef06