Sign inSign up
Elasticsearch

dhi.io/elasticsearch

Elasticsearch 8.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.19-debian-fips, 8.19-debian13-fips, 8.19-fips, 8.19.21-debian-fips, 8.19.21-debian13-fips, 8.19.21-fips

Index digest:

sha256:95387c5580aa804c97b738cd6db8a974e7d6529031e9501521e5e39529809844

Manifest digest:

sha256:e8715879fe03c62b13a46431f000f6a82be22732149e5fe3c958bd5b2aede274

Size

581.11 MB

Last pushed

2 days ago

Vulnerabilities

1
3
5
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/elasticsearch:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/elasticsearch:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/elasticsearch@sha256:17bbcb6c70ae178b155f5f1de89e3fc98690a442a48c797e0c43c94b45e5bc95
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/elasticsearch@sha256:1f041f09a29714173336e78c0c189fbaa54b3da870cecc90a350512ba0b4d4be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/elasticsearch@sha256:75b4122eac11885216a03d327fa10fed33f39e5c0e899c1207c93eb727f0654c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/elasticsearch@sha256:4d730ecd11cf2f78eb7c1d7985d0ee5d01bdc2f57c3fe41eb53ae04b66c62836
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/elasticsearch@sha256:8ea4928d588ff4ecd2c4a175c8d917bb7edbb42cfcfe23638e763eb9dc4c78a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/elasticsearch@sha256:ee887e25ca216b5242e7a885e21d2d865a725903623cee689a7c3b11f2ee5b51
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/elasticsearch@sha256:e584f3e35af125e20a3f58d126f5948f480f7f32d7c7ff2f98e249d58d77a433
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/elasticsearch@sha256:485dcabb0032bceb6af3fbe2f80e92d22885fc0158b0eec42a5cd77ec0a7ec31
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/elasticsearch@sha256:0c1e4e4dd0a7e4fa7bf30a13c646e64a38a326ae77420f71aee8877db8e8426d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/elasticsearch@sha256:2cb86f6db69562f9bc6869b6a53a485846bb1468a7a27f3fbf3bab1433efea3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/elasticsearch@sha256:8797245bcd6e0fedb96e6edf071d6710f922d9f419ae7b616de02dfb02549ea3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/elasticsearch@sha256:f7fc822cde6caaec66f084bbbb37f267b268fc243d9940dcbcb57e6f01f48956
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/elasticsearch@sha256:68455bedadbeb468335f9ab36ba39397e9432e4441c176f1349f1848d8d5b117
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/elasticsearch@sha256:29a2f2b18e6851f9fb56e9f3144f483de105d3db9489d649ffc5d5a50c7929d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/elasticsearch@sha256:f64af6f0ed626f1c259ddd469da9d2396f7083032bb9bc2b9e68d90b730f3d6c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/elasticsearch@sha256:2178d3f14a097aa01a6b347caa5aa8eedd2875339bf9f196ae938ea3d30cf2bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/elasticsearch@sha256:7e9a928efbaef9cab9c114f2a1c34550721ee317a370aedd2dc2e3ffd163d064