Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:f0bd6a2651bb08458b31b33b8815af87ccd20c21fd0e20af834ccb8569621ff2

Manifest digest:

sha256:447e883b35e4ee586dde58afd86adca91a17f69ca40eea623c73b5f202b9f484

Size

191.87 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:a7aa66fd14deb8ed1e501916a3d88ded4fcc9a4ac6756e66bbf16542d5b030e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:232f163cf0aa0174a2030f3fc7f59ab8d1fd3dd7f0afe6941820351027822ed6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:92c7bb8bb6db09c4b039884dff558083e96aeae25870e66bf6c7318f5eba8169
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:5d066ecc6e4ece68e6304f1f9f46f5fdc594fcc39aede5371b4d00e0c86070ee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:dd934b4123e60e5dd1e1b9e591e8e8edfbb724260aecd880d6b435a14d0d88ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:c6cd7e1c9620f008dba9ab589bc4c4edee0cf91ed922688f7094a41a917d1e0a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:124eefa119f30c732662a241145ec71b08a3d23bbf9a5bb1917fe1a749bf39b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:374fc36bfa38f1be5df64b4277a2787d4ff01bd8a285515ea74b65124df4b7d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:e24778a936be1847f13569b3959ebade2240fc205d4af45126b27bb23f4ddd11
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:a7e42fa44c9cedc103be046d0987a1041b6bcd5a853d7ccba58caff6dd403edf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:6a22f4262c2569bcdc251a35faf3b42f2910893c9cb2d56ccf13e51b32e8560a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:d3727312e4d05a8b58698f05e07dc6bee1b0ed5c650aad7ad750c3a7dfa23030
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:7881d5acc6dfa665cd56b0513c5e5a2e631c1108735be0d4fdb231144acedbe9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:5a97ab26018626313077ef5bd41d7dd3a85802e7092b351da4a6fc0c100554b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:88f78d8b7a6af8cb3444a29b2aa0eb185109302c6df42d73047aab6b70592dd7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:28c11908b3c6e6d45898f1659550fe3ec1586bdff39804df6fb25dc5f68e27e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:e3e12587dcbb3f8954988fe1a2eec2474cb14711afd1805045835e5438e3fbe5