Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.3-debian-fips, 3.4.3-debian13-fips, 3.4.3-fips

Index digest:

sha256:e685c07ce1db6ea8bac96066f88b14bd5743ca97c1634efd1fa6f23db2c1cc14

Manifest digest:

sha256:058db93df58525530e4b977f24efa1e18cd6069334a529d5350cca1c937f5411

Size

92.20 MB

Last pushed

14 hours ago

Vulnerabilities

1
5
1
0
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:5be87a34f146f96bb61611be4cac879fcf2460d25de79f75f059f77242f1fc7c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:baa09e2feb9b70b2c4b0bc6f8a21f6d72f1f76a7dcbf0f2a74e36872ef1aea7a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:19d9349d61c62267595184db1f93a76b0a4bb6a90c7d19381da00ccbc4651f52
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:077158cd4ae3cbdb0faaa43cd90f14dadaf782d0b598fe3c651033bd7ba20e11
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:8f415dc405b8bb23f7c2e22aa01d41050299bc63aa09a865c76315058481cbaf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:ceec0a8e91c8afce75d55ada9badd98d0b77ef4c85a6d95ca688be126d39c835
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:299b799dfd12fe98a0ef27954ee61130388e9d80b864ecde62cfae4a33bd20e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:74576abaa7b436c21d2b820d267a824a3cca5aacb1142db30c372cda3f600066
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:cec6a7ab8541672cc99992107edb3a493f804f9b6886683334c2549cdf2ba93c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:3521b97610e5204959b5554cf4ad6e194f344666aa68e60ad7552889af57ada0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:b4461479f05949ad75c4f755615e1c0c4b500ce36c601d93a700c73541674834
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:c81265e1b93efd620f5cf26ecfa3688abd7950211f0e2d10fcf16e44c78603f3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:12d1cb9dfc376745841eb936f6d37f7cf8e955b6ea0fce3e890a430587e8d89f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:0a4c1d3ae63f7f48219f175fec5ddce1b87647c3fc5fdecfb66ec88ea3082cb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:b1db9533c0d6c824341e8f7ca3cfc2c05278eff68d7598645336a751612d87dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:15adb54863bd4aa779a82dd38bd25c7901cdfe4564d1500f1cb43cdfe5100f7e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:88f592ebe83b57d5706bdb244fb873f5f936bda35ad4cf78c1e92d485d337a32