Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:df4119fb8d4446cee1861e9c09bec837925fb6b5ba1e2d6272183fc60b11fca5

Manifest digest:

sha256:88331eefb0fc00bd79910fd6073d51d086373dd0a8b7e30f67ab3b31826b12d3

Size

103.95 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:a4b5c3aad2739469ae221fc91a2059a8d3c5875f1572d155f363e78877229858
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:545b5d90c4ce1c2f192278572376671113d93694ac234a97986db30db9e79a91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:b9966f67fcacf0e5d86380b519ada41d17252a74c273544dff3f97640fccaa46
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:86df039edc8c3b62313604d5c6566ac1776ef1b258fed7f3e3443f789cc5f0e0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:416567d55111f0986958715a0020c5fde3052d318cb9000080d38196e5bc2d46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:6fd4d15db246ef7e6e2e72586f531eae3fbf146718dbc45acf06358a2b25e47d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:29a089ab25d95c73aec8d87fc40dcef0c3aea26580bdf9f08b06dc55bfefe5cd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:c2f94756adfc4fb5c589e1da7e740cb371ebc3093fe61588aa0962bbf2c5be3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:3491ad95b95313839e4468219e35fd53f1a8d60f48930b5e322fb44cabdd0cdf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:98da248f34df015c8b188b4350efbc76f0aa55f12c1561fc7d30d5077884e10d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:f5318859522336883ddd505b2004c6a0870330b1ba74a969c2e67efcf712bfa3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:860c8d48fba0ea6638086f91807da940bf833ae020b834e9694d010586ef44b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:82f206e70dd366a0266ea2a63b25f339d4074436e7e65826ca8c12c71a9140ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:b49587c71f115ff6e67ad84440c31eca158208f17fd69ce83d5fb286a0c1bdbd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:39f3815bf2b05d2cac8639647a64a7b4cd6235ebf90c050723793ce9a2a932fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:bc56523d9c96e1f17636502dba275d30466135c5d3aa8e4ceb8f47c3c63dc9c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:562b954cc8bb3840b36810f343ad074bba966d0318de935f433b2e3c752c0ab2