Elasticsearch

dhi.io/elasticsearch

Elasticsearch 9.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.5-debian-fips, 9.5-debian13-fips, 9.5-fips, 9.5.2-debian-fips, 9.5.2-debian13-fips, 9.5.2-fips

Index digest:

sha256:3b4eaa33fae40b2a4ccf508e97ed26c38a06f1bdbe1429b0884c508b58733cb9

Manifest digest:

sha256:411782e22581b499fe4823363ce4a9ec4502b35debdb0b9de9e538712a9f3f7a

Size

724.39 MB

Last pushed

21 hours ago

Vulnerabilities

0
5
10
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:c558a96340e9f5d0b50783dbf93d69b08430ecb99ea7d9859349c0e638194af8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:448a8bd168e50970bd28a8c11b13df5faf7b41907a9c62a1fbacbe1289b72f88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:d292c537a7970ead6a6800a1b762ae96e21555fd6f73d96ede51d3a6becff19d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:942e5205a21ecb3708680593fce9ac51068f8b9c359b94f583bb7e127995efa5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:0a86412be995ae3f918d09d8273b6d1c8ba4c47dcc484c74ca6559172907f574
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:3210ad988179ffa862903898148c078b10e2ebde3183a8d36afb9d2226973225
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:7046abc6cc5b22d8be102de9bbc56fcf0c7e433e209d93ce179585c5f2545ca7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:0cd783318488854a570a0cb4f627a5ce68125e589fa563e563b88834a3329339
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:6655646d6c811b5e7178bbac41b7006b34e4046d5e067cd07985f247eba5f3c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:ab26784c16273e6e3579860f2b6611c28b49fc673382e935419f2b40c4de625a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:60a02088b9e69be0406cd7df0357e87ea3b8620824cbb83ab5c708708e073170
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:934dce00771d2250d55a783f8dcebbde3bb63003aedb249a7580ee16fadbb77f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:5dc038c082cc4d06d4268de41c04b4855149b77dcc7f5ed64cf3849246ddbcd5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:4b04d73d2b2811240acf71bafadd2a0b4e2c6f4e59281e66c6c7dc7cd29f2f63
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:4fddc0341fed3a9b18f69dc323d2ff6e9016ff3ec8f224c4d0b3e016beff4ac0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:8091d6b01b35e7885b511b4870d68a2c8a7c9f52ffffc6fd17b84e39f7ae48e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:dd409b72437b2e59c97947ad1ecd77aec8e6738cc1859ba7792490d1d726cac1