Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:bf8652915f631a084f1e2bd67909f373cab50960663b75f17d0528821b9066c5

Manifest digest:

sha256:94060a59a1c11cef483fbe41732431467d60b64e23c17866cd2056970f8c9b5f

Size

191.57 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:9515825966b5d12194f917a72cf6553ebdda0a93eb7bdd920d8c39fb6c74f889
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:8d8fed77ea12d6e027ffc76f9b8e240aa46633192eeb8aef0e69332f02015af5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:d03df226940c60493dad92efaa24da87de6185e09b57f59224a7ee7a90184bfc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:6b824d4c148bc3fae2ce74507652af18a4b463bc383c4b5921358554a4877965
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:ed0f56ba67f480b596b6307b82f588195cc4b71053cd285c1865f6194517c016
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:af1a8b609a7f272b09c3407a8625b54f381c7d786c5bf8d97780b663a19fdf1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:18f9801f2e2e8275b79eb786063c5411e6eb4d15f1cfde87e907011b4fd15686
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:602f74037c87230b2f0926700f11b1878932de245b21856f8783ca6e6b55378c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:fb9005892963a8b9252f02892f89cd6f38b696f90393c25c885ab90989d2bfc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:965d7a01b5dc112c179c14a0f82b112224b5c7939c190fa6956f99ad79da636f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:3dbca20c17d7315397c4285d6d941b3cf94e905ac4592a8ec5149d6c5d8ad013
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:9b9d5e760e28403e821310ba2712e9519b160a74a84a2fbdb8ff70a2885411ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5386972c00f3d252b2ac301c617653619ed2a91f002d9bce3694694047555286
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:6e49947a6a321a83f6844726533ba4266dd38f8798aacd7e28718cd724f10a05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:80d562b842e6a4a05637c6cc00f435a9df46561cb86a392d26dc7bb6d1f1a86a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:143f961ba1bc41413452c2316773d87564aa032ead81ddd38d69f83b535945db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a9de2a6264925510e4cc6bc1abb5f3139a97b480c9bbe870bc3a1b03b0509e2e