Charts / Search / Elasticsearch digest pinned cosign signed SPDX SBOM SLSA provenance amd64 · arm64 Rebuilt 2026-07-26
Distributed search and analytics engine. Shipped under SSPL/Elastic License, which are not OSI-approved; OpenSearch (Apache-2.0) is the open drop-in fork.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version.
Deployed image digest
sha256:367dc3e01e24839f6ab7177503ac32d6a6c470665770790776c9eae17e4a657dChart OCI version
oci://ghcr.io/quenchworks/charts/elasticsearch:0.0.13The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
License caution · SSPL-1.0 is not OSI-approved
Elasticsearch is source-available, not open source. The chart carries this note prominently, and we do not represent it as open source.
Clean alternative: OpenSearch (Apache-2.0) — the open drop-in fork of Elasticsearch.
Security report (Trivy) D· 10/100 9 fixable · rebuild clears them Full report
Vulnerability detail elasticsearch 9.4.4 · 9 CVE CVE Severity Package Installed Fixed in Title CVE-2026-54399 HIGH org.apache.httpcomponents.core5:httpcore5 5.3.5 5.4.3, 5.5-beta2 org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers CVE-2026-54428 HIGH org.apache.httpcomponents.core5:httpcore5-h2 5.3.5 5.4.3, 5.5-beta2 org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks CVE-2026-46968 MEDIUM openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) CVE-2026-47021 MEDIUM openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance XBM image support (Oracle CPU 2026-07) CVE-2026-49844 MEDIUM org.apache.logging.log4j:log4j-api 2.25.4 2.25.5, 2.26.1 org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values CVE-2026-49844 MEDIUM org.apache.logging.log4j:log4j-api 2.26.0 2.25.5, 2.26.1 org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values CVE-2026-64607 MEDIUM org.apache.httpcomponents.client5:httpclient5 5.5 5.6.3 Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS CVE-2026-71497 MEDIUM org.jsoup:jsoup 1.21.2 1.23.1 org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names CVE-2026-47010 LOW openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
Close
Security report (Trivy) · image elasticsearch 9.4.4
Install the chart Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-elasticsearch oci://ghcr.io/quenchworks/charts/elasticsearch --version 0.0.13Deploys image (digest-pinned)
ghcr.io/quenchworks/images/elasticsearch@sha256:5d0a0344abf06526c9d851326cbb80a162c459dad7d5465f438773e8992ba718
Chart version 0.0.13
App version 9.5.0
Chart license SSPL-1.0
App license SSPL-1.0
Signed cosign (keyless)
Values schema yes
Last published 2026-08-10 Verify the chart
cosign verify ghcr.io/quenchworks/charts/elasticsearch:0.0.13 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.
Upstream project: https://github.com/elastic/elasticsearch