Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:70ec8495bc60dc1cced1e769cc59aea4e2d02661ccb144b60152461fc66ece41

Manifest digest:

sha256:072d1c387aff73c570da7b6e9892538e300e6b3195127ea4cd626d0946cde71b

Size

180.53 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:2e22ab5e9f500058fd1a9b93f8afdb9a0706020cc28befa95d25666397582283
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:d48b8ed34de58966f425598b45c573f5c342bdbf00c2acce3fe6211d492c6802
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:f391b8e0da933ce333223de92f5606ec60f5f5ab777355ba38fa877998fd39d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:17eddf7aac1fa8192a13dc760b6b96910532cd3616f6c7efff61704106ad7412
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:588cedd5ec2a22f5233432228f25b9c693b191f49b96c206109771e53d8cd815
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:23c56335c4f4181617f2de96b42832f0d013d3d454e5261be1847c95847e0e65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:370b29ee6484bdc3a832ea9d48079ddb5f9e722abc23c08068ce8802563c476d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:00b5be94c7b72ef6faf9ebd3115bbe7cd8194991235f938970e5ed65c4e9e450
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:db3e2c78496f0e3454921d5727af10301be345f869e85b446facea1ce29792c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:c02cbefc1b26c4287e43b2bf4b108e17d2c388ae1b22ba0ae545622d4abe678c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:fb5a5e5d3f79b0907ca8bd36e06326a2c7fced788f2dd6150c7cad82d5cb881e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:a668d5af930c7843e6c5b9690a2ea06b089f7f1eac8c78fca8e4f881b949f8c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:dff612a57653fb4b61a3935bc499d7ccfb0513cb4cd41c5e14bd21f1356a71d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:f7b0910807921b00273f66e739d2698a06bc7a7a7b2e02f9bf44ec11b3cd2749
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:7cee47343239b35d0ad652ae5838e1099fe100f76a3cf3457ce7857f6113a003