Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:ebaae4220977889a8837ab3360268d1df4b5810be4b72a6e9c54651769a0edcb

Manifest digest:

sha256:2cb46dd29d78a536ca88bda2a0d4ef1dd84890420f202e9a9d7e1b641fa7752d

Size

191.85 MB

Last pushed

9 hours ago

Vulnerabilities

4
12
0
1
4

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:90fd9a08f5917f1111dbf744846513839bedf7a98f7fbc587b8fe13bb083ad32
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:b85bc368efd6dee4cfbe2acc82b855261fa81bcf0e78e2fb806d4e3d2289da48
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:60958d3c21b2ca7c3f7c34deca293cdb3d74e2d87a9424e32d2033757632fc34
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:a16a21a7994f102e9c06782941f7e45cbacf986976162489e6a1cee6fb257e39
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:6013998e6e73ab213d7ef55a04552a2fcb80346553fb4dbe35f271dc6ee16b64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:c81cd199a6f4b53b117ccf390da0ab652abb6eadb658de758c34e27e01cf041b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:5028fd5abf1be2582135d161422afce8d1d58ed2ca951798832436bc564df9ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:8c523c1fb446601f816d32911d8b9543ab594a2e4f83ab1a34b35fdc7a44618d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:b626a8cb6eeccab52c37eb6b043813400273093fc81b80e3ae65d0b30ae5fd7c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:23102e3b89ea2f22df283ea59a49f337571717462d8bfb37039f1778d6b601e3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:ac551f2c9e71ba4a55997d8025838bb86da9fc1732866e0a74ada950daa1ecef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:006ee151bacb137dada37ad81ed03d43602d9d77ef86f89d27a856b47c79c2c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:cdf499253544db3a1c7fca5f264ade917cb8d9bfa6bf24f7c57e0066c6c7b541
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:cc96f69943735b6fee3bbfc375592ef712f16b97b81152c80afff8fcde66670d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3e38c1e4d556702671370cb19e13ccb1cac85627571b9dc0f285a60b27b52da3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:c62a42983f5a2120c55ea3ecde496a20d24901c8ef47185969c9e101fe16e30f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:f81e190dca58c4c8d48831169c138c0b8b99b84a9fe85e38743567974699ccbc