Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:0256d2e36429cc435c1bf2228ad2066b41b032b8c22b3f377aa7bffeb5d8e8b0

Manifest digest:

sha256:38c48088f3f8a6612288995c348522c670a26db1ec0ca3ed52bb6c09667ed188

Size

103.95 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:d97f73ef6d23a43d21be5e3cec1bb32dd6cfcfdadd37f72b685ec677f02c16ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:e1af60b775684f2847ef18edec7accd06dda61b487fc2d38f14f5d93bd1ac570
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:0d3fcbbc540aedf3740a056e19266ced2f902ae6e144f95428e5053533c49317
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:938dab140e3268b8f38cd078b109a833edccd07a06333f670f509874169e2250
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:170933b4283d347343a8c9056559bb95ff2749059092629464942d2c39d7c1b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:b1b3410f674a817cd371d44d9769944befb0454735edd7201a006503675f6a0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:4dbeb611887f8303ddc0f832d8ac2559b0b49604e480a3da00d4c319303b30b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:8e07dc844e54db5160e9cfb7442b563beb3c473f4aded8f223287c9ec5a4d8be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:f4ccb5a36915744e16bcb28cce2d701aecbbe5680d2e2063a148ea751e1c3914
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:94ffd12a844da1c27735909e3ea9878e9c6fe9c8e15c2da6c90916ca6f6453ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:9792878109b3f2c6d8de57f59ff09d02c24c3c283b630e39964ea9894628882f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:428c3091bca86c1aca3d3b551750ce16f5afe742159152e452680048558d4e7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:de567c2c8887e5f3575d096f967d9ea6ceef82c2ac3b6e34b8bfc2f0a25d2887
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:2be0d6feb1d5e1db5f61c61b23aa88762d6ddb50cf31810c5d2fb8d90d29678a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:920501ad599a946246ee39af92fe9074745c563a5ac502a3183b6f7ea09b6efd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:c2636d39270300655a0ffdba68d4246c0a1e57c4fe61db15ed44248458f2d2dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:09ec134a23a999c49805546ee3517ed6a17d294e62b032c0fe06205e01ce0221