Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:2d0eb853222d1e179c5a8a78d4969d5f1a45c51da30e69b6516733a01b565808

Manifest digest:

sha256:934848e997a4dbfde4f0039d6d4327f62fd5d2135028d9a55e5c1a39a8961631

Size

63.12 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:f94b7eb47cb780c9acb551dbf82631464eb6f469d9ef7c8f4201a97f359985c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:4836e00ef6760e6ccc0b67d925d063ab49a64f52a1588fd23919eba6c56a2455
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:73872fc7ba057c0e197196fd0a626e2ae280e5d3cffd727639b8c7ee586714aa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:cbdbc7e223653c7f2171128e9c402ea1cf4d48a10efb593d4d325000460e5b84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:80b36c051057c28ec610ee4dac109bcfad12ac0b1ff1e22d294c983fe43a9440
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:fe32a17e55a12c07b63b50b84844a6f46812ba98aac862f16c39dc4c4bfd7715
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:11e2cf2d0a2bcdb7db73ef56ad6c70409f236c28876ef2c243e83f2b9d58eba4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:5fc75268bd86484a054aeb4a2b9ab4df0e76d2b2883ce9b2d9d45a5b0a58d7eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:03d3510fc47117fc40ea99b4fa115e1bfbe7500b8cb9b78c438ce8f36a8bb108
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:91dbe3981285cb422a86ef2a4bc8d631cf60a5b1dfdb27c15bf211e55edfa3eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:51e0fd94b7b85da97e1896f3c1b2b7bbec6e4c28c6cc36fcaeef47ea168c18fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:b2351634d331e03a47e0b890fbaeefd916a988662d1c144d0762ccd602f47edf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:80d0a5239f19f6278485f0fd6bbc2839f223a1af0f9f80fe8de4d3235c43f43f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:e79a0404184a1a88bcec0cacca5a4a2059e2c8f35eca6f7b9e5d14523b131314
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:caf43248b8e3b070dc6c8bc7775beae88283c5637bf4b3c2ef541784265c49f4