Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:192dca2d7beb1e449b5d3a88797f3a9f8b0dba836523984b077b3348f89a89dc

Manifest digest:

sha256:1d4193519a5c786eda0382f106a93ed410a0d10d212f136f290eac50dabcc1bc

Size

191.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:8f05f950f842d1b3ef9bf2e63bc79501226f9f3ec6ba5f34751195024a2a162d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:5789a5c0bcff7f0c534fc9223065ffa5b78cb5a60b9e219756cf0eb33abb841c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:068f9f5b899ce7bac0f2472ace5b4f71d846ba0a33815ca86adc8f89a691e977
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:24b24248767ff6bc8f3ab93ad4a92623493ebe87b8e41165defa290db8231b00
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:cca91f0d73b65584edcb8961fc1af20a32b2f9c3c0a05654897b5718d8e73124
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:e710dd4531e6336946c2380967e6c9ea890d592f27f2c34911047ff70f9e4f91
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:2d717bb750f54c3d812e7da8e97b241f67fabe4fd0137c3641e46c7cd81b0aae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:38c43b60a319d711612a683b73aa8b98a22f5c08a405f4bae5af82b1c31eb6e4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:3ac54a24fe9c0b1a4d39c873690709f2f4fadb734930965b8d09f450820a3486
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:fca08ad0bd2d433ad1cdb70319fc059b276051eb80cf1794648b3dc0e826115e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:ac0d90baf5b2538fb99b1029f6a1bcfb65ffe2b8f9ddfc1d16620a8f5747c7c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:d6a2081387edaf4644a575bcc79e61f3b38aa0e3366087e9aaac84829f04d04e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:88a31f2ae4127f099db3f2108a3e17af22fe7f137deb6df7d864cb1983f2a356
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:0c1453d0a790dfdfc5cc08671bdcdc05c032853d82f289b3c9bd0713f76423e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:4401efb156a58e6f97f77794f9fe4a02754835e89bf3f2937f73064f8c6d9127
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:af0dc0fa57e61114fc0df36bbf2c841f9b59ee9d9277e41480ad341c6efb8b24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:3d5dd35fd7169ee6c0f5a78d2db3265af3bd46c07954b236b09fe50a9f78a3bd