Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:ae0225e849fa513ffee9019040949262642c271e89c06cca9dcba2bfe594397c

Manifest digest:

sha256:d7559a17e393a735a61cf661688dec0d318dd608b81c956b35fd9566f637e73a

Size

191.12 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:cfb45e35425be036af1b93c1d20bd159bfe548d7163f3044160d4f12aa7b0eb9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:bc983bfea5e0781c7a422fa851edc68b63735f5564346b13cb62edf9941abe36
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:ca86568b402f391d16d18636819f6bb77cc063277c2cff7082c5d7f17d7d3bf6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:20f56f812a58fe64ec08e6195cceabb3fa2bb8c35d9394d44e0c3f4117dcb97b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:051a6bafc3f4af4dbae8104a931c709c1bb2ff77b698596d0af36b3034db8d33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:3e6d4812dd5f1c03b9d2bc1fc88318a7dffe7508ee1dd89a89103212fe6944c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:41d7de53cfaafc97888acb4a752d5f6599812c56b2148a2c26389a64bdd10be1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:61b3aa0469dca2cd0427107a23e82852cb77eb401f197463dbd37dfcf303f036
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:c7f529f15cebfff62e3c9d5c516d27c118936a6bb44447b4260626b70d304914
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:806bb6b04b1e00f6eb71eae8746c7ee05444834a80ad8eb4efc28f84da700de7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:20757e8131c20e65fe1b5dd2bbc34e9b821f90ed408cf2e8ad42924cd8e28101
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:dc577b1f4aa3cdf1dfb75b724b469a30fae7aeb6f2d42a5725b748b82ce289ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:412244eb81bb6cabfc131f69d6037a8236ea2e795ccee19bbf6b28d5ec4487e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:a6cafcaf04fdb633cc895ae05c4455106da78adcda6259c1616e154cc81915bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:4e175586d45a22a96ee6478df24aa0b3143c311926c86a6afe8b0ad8f12dae57