Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.32-debian-fips, 8.0.32-debian13-fips, 8.0.32-fips

Index digest:

sha256:bf1b2e2b4f71beed15d3585fd8aa97ef84ee530b3c441570198438315abcc39f

Manifest digest:

sha256:75fff4dd37d9d19cb6293ab146943f8f3b1cdd4b4caddb2a2392a2801a439ef9

Size

63.87 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:95001fdffaf2fb9f98f999c382dbecb00482f945e80fe833bcdc626b48b0d203
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1d2aa05424f43c866f8f336e47e486b31ba548c7e0581db074ee278ce0f198cf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:6c897db381c9f401f56d0d1a55af1d767d528295467efaa6c6b46e881e2add38
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:111ea2841cf2e8486faf6108a65bc03bd2c2842e67ce669e6d70c06341918d67
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:0802cd2611d3a276c826ebf6e1a8bb8b3c240a8e8eec6b491d9d02aa8b2a6eb6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:68e634aa7016356f2ea69f011ac008743fdd002dc3149a6d7c8d4b99aa8ae90e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:2ac574ebb3bcf8246cdc6d4cffbe0954e175abd042f8ef4a38e0a084fe910610
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:ef0cceae6106d4defb5fb44188bd603cf47505689d95fc8f46700b24bcfca9a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:0244c824a4f3654a2be241d86eed9458396eef708cabb8c89059c909ef923a6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:2760488436452377ee82f623360c1b1d8db145cada443f62c18983e84b3ab659
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:34756cfe8d74d2f52fdb94520f076e7986099b58d45053cb4bbae985140c4f9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:f26688b8e1fdcae82a2078e191b485b2739dde95844f84fdb662115fe913ae8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8cc6fbd524ea085dc55bb3f14c231745499c48d3e69882642e7d94b4961a5cc3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:22bc4e04700990504bfda7af84e90105dc3b07b69d3512c6d6eb22b0b2056291
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3c079d8692795f2630dce08fb178bb63e0465697f9b97612922324a827f9755a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:4b83dcbc8384a1aa390727a6b5dc5c7a1c41569c17c7a26d1e1fecb60f080208
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:836c2983eced0e1f1738345f1804ff600fc477c37d532eb0341e2398803637d6