Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:bd3f4b25ff1c61b5504b7d0723ecd6bd51c1b21a45e2923ddd7614cf7b2fc567

Manifest digest:

sha256:ac05e01ac09ec4dfc9d87c2e31b8cd4a36acc75e08757795f7cfbb1f384024e0

Size

103.95 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:c6bd38d13a17714578f9161286b14715b6c696da09a1aa46c8eca7489fc23596
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:dd8276c6dbbee2a1db6dd723965b717f39b07e13deeed3e422b2c3d68e99fdfa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:3fe3160aab43df6ebb37d670b2d11722c491e44e1f54e0a23aba574a7e9ac29d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:e839f9ce6d95fb200807dbc27563cdff17e5457a88724566b91aa1c0089b863b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:8323bffda9d3632055645b5b9fdf227aa98bc035719be1fe7cf842633af645c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:321ef27be40cdf4933e9842b13487c8656e0cbb00bf077ee01e8764d43d579b6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:f263bb4861a43e2f77a47af566153a4e5a2a1a3b41d9426623d613510553666e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:4730de1ac47243b9af562425fcc0c990d7e5accd1e962afa5303464f47507f50
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:6b022992b68d4e215deb52cf0113592980de56ebf188b5364bc22cbe46b2aca0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:d3b158a87946c8aa4c5de72b1e7726ac078f980f316069f330d44ae032a0cfeb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:e00598c69b1fdd5c7944dec97794b2ee2da4710dc5d0242b1bacda7e6bcb7410
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:61d6a239f7d349898c70f61ecd8fd92b9dd30f90210aeca654cd157628cb7db0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:e0b0fd6ab7c9a75a7a2194b227619494376fe4f3dee9258ba22aa754e95d702e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:745a1961b8ef1415000db3ee0237db0451a80599876f7a483dd1137028414771
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:b8bc288c03759646aa9a4c472ee3bb64e2ec7fe2c329d853230eb60e556e061e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:34e14afc69c9c55152be7d1de314f233fc1dccf8ef026ef265f5a60a0c5e4fd1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:21c650ac2cc6880efed08729c375425066d72adc96047f04f3457024191e12ba