Charts / Search / Elasticsearch 0.0.8 digest pinned cosign signed SPDX SBOM SLSA provenance amd64 · arm64
Distributed search and analytics engine. Shipped under SSPL/Elastic License, which are not OSI-approved; OpenSearch (Apache-2.0) is the open drop-in fork.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version.
Released version
This is the 0.0.8 release of the Elasticsearch chart, published 2026-07-02.For the live security report and the currently deployed image digest, see the latest release .
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
License caution · SSPL-1.0 is not OSI-approved
Elasticsearch is source-available, not open source. The chart carries this note prominently, and we do not represent it as open source.
Clean alternative: OpenSearch (Apache-2.0) — the open drop-in fork of Elasticsearch.
Security report (Trivy) D· 10/100 9 fixable · rebuild clears them Full report
Vulnerability detail elasticsearch 9.4.4 · 9 CVE CVE Severity Package Installed Fixed in Title CVE-2026-54399 HIGH org.apache.httpcomponents.core5:httpcore5 5.3.5 5.4.3, 5.5-beta2 org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers CVE-2026-54428 HIGH org.apache.httpcomponents.core5:httpcore5-h2 5.3.5 5.4.3, 5.5-beta2 org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks CVE-2026-46968 MEDIUM openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) CVE-2026-47021 MEDIUM openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance XBM image support (Oracle CPU 2026-07) CVE-2026-49844 MEDIUM org.apache.logging.log4j:log4j-api 2.25.4 2.25.5, 2.26.1 org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values CVE-2026-49844 MEDIUM org.apache.logging.log4j:log4j-api 2.26.0 2.25.5, 2.26.1 org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values CVE-2026-64607 MEDIUM org.apache.httpcomponents.client5:httpclient5 5.5 5.6.3 Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS CVE-2026-71497 MEDIUM org.jsoup:jsoup 1.21.2 1.23.1 org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names CVE-2026-47010 LOW openjdk-21 21.0.11-r3 21.0.12-r0 openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
Close
Security report (Trivy) · image elasticsearch 9.4.4
Install the chart Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (pinned to 0.0.8)
helm install my-elasticsearch oci://ghcr.io/quenchworks/charts/elasticsearch --version 0.0.8
Chart version 0.0.8
Chart license SSPL-1.0
App license SSPL-1.0
Signed cosign (keyless)
Released 2026-07-02 Verify the chart
cosign verify ghcr.io/quenchworks/charts/elasticsearch:0.0.8 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.
Upstream project: https://github.com/elastic/elasticsearch