OpenSearch

dhi.io/opensearch

OpenSearch 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.8-debian-dev, 3.8-debian13-dev, 3.8-dev, 3.8.0-debian-dev, 3.8.0-debian13-dev, 3.8.0-dev

Index digest:

sha256:f4f61957e9b1af835eac46a717d6d0870a0f9c02feebc44864083c687b7a3ba2

Manifest digest:

sha256:b34e0317d87805982590c5b8474d93c6faac460d61cbd1aeaa018e3cf7beba20

Size

1022.44 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opensearch:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opensearch:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opensearch@sha256:f1b2e2d6330d318d721fea811d54a3df00837b9b8a19f2bb757266ac2e31de12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opensearch@sha256:63cde1d9f6578354154fb72b3a22d128f7c2e6d5579786e48794b0e8f8e5a15d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opensearch@sha256:b1bcfe43278a9e8f91f6470e2b85caace14c2f1d8597ab325404188b77d0ddd3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opensearch@sha256:b8ee6646d476c609d0d03fdc0ca07571b161d422cd7fb9ca553c90d1d94c43ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opensearch@sha256:cd91a14b758ed51c15c2db8ad3ae878f850f00fc5273933db9c42ea5a8a2258f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opensearch@sha256:c990aaec1e685b8a0680386ef1c33e0eca57188a2d07e013af76d29a2886a870
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opensearch@sha256:5b83fa0458193ca119f29be1ec508e4a5779d98ea366e9fe1ffa119c035ac64b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opensearch@sha256:ea4c3894af399f62c73962fbf85d6b3a9edee4457567a343a31a25768892a373
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opensearch@sha256:e92b45c6dd93d2e2a959c3e7320462921729c10848aa549fab6480749b1a86c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opensearch@sha256:b93466781bc99c103f841d5d11b6a7e4565a1a11fe2abe33d760f478e01f3e08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opensearch@sha256:79ff94e2349336eadec495516d0bfdb0a838beacd4bbf810a6476f6c1e4fb8c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opensearch@sha256:ad6bc646f716aa77153ef771555307e55a72385fe012f9f2c6863b38bc748be5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opensearch@sha256:ffa1f719c525828329a12822d474f60450ad6eee891a89f8a9ba767dcb08dff3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opensearch@sha256:0b132da7ff87f1341a6abd7b94213ba692c73e54c48eed464ea73693c0809137
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opensearch@sha256:b34c986d727f2db47ed258165855a5d3c516ea606c598d5b2e55256373edfaca