Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:0fd47d3ffd4aa7ac7bf9b2be669646c91edb1cbf9dda4e26f350857086364ac8

Manifest digest:

sha256:1f146a8a45148e9be832de3ea2a6d7d6056f53b3e14cde734cf8ae646ebf79ec

Size

180.75 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:5ff6c8105b7bcf55ea6f60c6eece91aa90cb18f36944a3daaa8d3bad622a6cc3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:2f6a7e401b78f8eee94e10334652129d49af407b1938406a1474a84b4fdcb491
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:27632b8cc4b04ab3a4c18d287c48ece366d04246543e54f24a709b9bf8c52600
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:3c8dc8af8cf8fd39c0b4a7ee63d7b92bfe7a9a2ad74206a83d1906e0e41a6e38
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:4812f742934fccf77a95a81d22b8f9fb06c4b6d9fdc01e256d94afb4e632ca29
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:de6b8855e38554df036c81c3eb33efa2e56de0a07e90c9fbf0c52174c4c2fbf1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:1936010d5ac8f6a8a849afc4e7b5cc26f7793d410f034f68830a3c96dc5f12ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:ed6e96cc1f804c00212800967fcd17dd0fb8793ff5183034255c5d7cb8447bb9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:fa3ea9686b576a4f217854ac3f4f6868a12d0981e2784f91daa8f95be1222fa3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:80e2a317188875a5b9b8f675ae5a49cb48f77c1dc756f46c9c4404def7b2568b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:a4ac0c7816f9b5f2c0ae7dc085ff68653ca8eeac41b9c405c2d6798a06d3a9f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:792a1de76d745ba2b3714fd67bd499f9affb1c32f6a6fd513569cc53bbecb053
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:b1413492f056d6b45325c86cb9d9c2eac2bc35f1a6d8fc27fcced1cb517e030e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:b39b7e19d1fdf77cfccba90d209b6d5be33978ed36d1e6ed593dd281a282f805
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:c7d631c3ba81aa76ecb83382ad376972043f9409411e866e50ae6898260dd13e