Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:49483d33226786ce8e7135358766da47e13472390b499982f3ed2e9e0e11e95d

Manifest digest:

sha256:84423616dcc4ffdabd487ae5c8eebc4c1fd5b97862c26347fc090e8cc47f8ff2

Size

191.93 MB

Last pushed

3 hours ago

Vulnerabilities

3
7
0
1
2

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:f30e3d260be6b83b6549b6932e36a6d5d6ce0fff6dddbe0eff8ae1414aebbec0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:dc6edfefca4c576b114e38afa1d5edabb1162fc0a6255d100ee1a436b50ae0d2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:d8dc42a775752b2be7673d2b9102a0599e7ae701584fb3b05345ad0fdeb4c198
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:279a10a135aa6b1f5c31e9edb3188f1e9a27d1a9efc2d91a6f2f58d0cc816a13
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:d12132a4abf8587f2a024e6ce7b1a38976c23e4d9af2833c8f11882cf0fa6b95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:e00a1f3e0c4fccb432b3407d66c1c648a300eccfabac096f0c89adb02ccbf730
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:cc2e3a2fad7d07fbcf9ed0c03abf2ed80ac054922c0baaf4eff6e8d80df29998
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:80cf59ea91f9b90699125c824378ebfb5f9f97a264d8b4de1ae3bf49904a5554
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:9412be899366972fdce83f519a3f59d3f6c212d26c7ffebcbe86973abe1d192b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:30d68ad2d1b5eabd45d6cd5a6130e7f8a3ceaa88c97281957f1868f5560429a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f2d3a239c62c85c3a276427b4b0181f2dd0692122ad26fdc0ac40200082ffad4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:6da0618a7080f8de707de8a8f57efbbfb3b44718928c3da71c09c359ed378561
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:a49a0c767cea64fc2b26d2dc978e199fcfe533cab7c70b6a0462d019b2178193
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:fac9126bed14a888bf0ab8d5736eb6d03decd78d139389717c2c3601d3d91ccd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:104754fd2ddea41422fa418ce3a2849d6dca3ea2ebaeb7f5dc80bb9dd4bb8b53
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:b5cab7be6baad3d1f6d6684481aec130c1f1d01519155875b733bd3e23188a49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:330b1fdac7433cab0ee1ca42651b211539f94ca4df8acf6f0611dbb05eb93458