Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:ea2ce76965b9eccd83793d0ba9306eeef9ab2b2660cbf27fd2338b9a15b8ae4c

Manifest digest:

sha256:2b6a5e4e40e39d977da4ea4ab51e0f58718a414282d44f78fa175cad666f74fa

Size

63.12 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:e8674da3b3d0c4019f10c439c630f61037ff72740b2f9c4684e9603a1e4313e9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:8de08acc2c4a7cc4022c60866fbb2fdc056006829c3524c68af034753cf6c961
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:b8f84134c8a7e3dfc770c822fd9b0ea81eb068208dfa51ffac749c3c2bef3280
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:36db6bd440f487534fc3b52ccfe3c473b91a0fe80a17e0bfe50b423fdbfa6eb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:631bd903982c5372104bb5559ddb6f7fb56eb078df2812ce3e3a77409da4ed6f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:eed5fc3ac3e512a2a9202362c87f82f3b2cdc68e748543d4b401ecde72785b1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:214795847f0561826c9eaf525035b041848be9d7e1b33663bdcecc3a30c6a7eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:1d9cee28686990f1d0e295745cabfa3a1c0eca18ceabdb9e38f809b4efb344c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:13bb68efe591004d3a69169b885dd87f748a92589dffe1d8cc5610d762d3fe16
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:3d72bd1723d77f05dac9002fa8d3b830829498f1e22fbaa59cbb1825b53b1dc7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:db88b29350790695922741933d4ca38ced12454c9d32eebc20fef240da90651c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:97d55dc186d8039de0c15067bb3a24642de5f1b09d2341fcb0a9cbbfc01b9d5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:4a11c56852db6430c145011dae42f8f5d694d72bf87658486766ac584bd36609
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:cfceb52ba2e14382228f4c271ef103184652b5f4c60fbfb01272df46fdcd5776
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:7533f07d61be014c1e5da390e8b4c6b2221a10b3ea3647b8d45534b7ea4fab96