Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:dbf34a78481a8fbb6b0b8125fe47433c72daf3751d1f7bb3da05a740efb4d635

Manifest digest:

sha256:65cc5f70c8b8ee3c8b6b76049831633bcbc6d55e2026bde8c9efbbf6016764dc

Size

174.61 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:afbb6ef54f659e96e736456d3ef1b9a4ea9b0d8e2f55c725fd55b205ab293112
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1fb42c45d18b46f7599f4fd544780ea7f3c06daa0fef06e0cd65066188a94c40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:4cf1d7bfbb7232cda84fc52e7126fc019a9b26392eda7de43b9fc9c5d0edd991
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:398b1431cfc36a4844367fe92d94bab56a82b360b299a1faa87d45b45a651b59
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:9b90eaddf66fe9c36f5e1fe9d5ebf4723b8a67205e750d1880021933e03c4f04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:1d96da2b8c58722c72310cb312ebe47ea841059208e4218c9c889cd29c7da76c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:11c298536588fa6c47536dda5cc69e39e39062cb8dbeb42216db3b26c4219bf9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:5f128c9a7bd7a82a0eaa328809a14914b832b92e26d96a60d049e51eb5e39030
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:1256bd905eb9372333260384722f38c31dff9b75a17e14720b00c1303248c749
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:80cf8e1a0708aa62e8598191ad7d16538abc5db350916edb32876e105ea9f03c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9206065e68a5c0e6a570eede48a7f29b4d27baa2c33e6157e80fff4f1100b0e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:0c022ed3b33d345687137aed50e97ec80e34602e9b8852f072430a2d9527610e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:68b2408080ee4d6a983dcbaaf519a9d00b84491a8bc364d1ec6317bf2839230c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:163f0e93988b3e55b7d224617190ef1fa5cff7277cf49189c4c2efec9129ed15
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:ff92f5b6e10db589d0bc7f2e473b4227e20db7e8937e1db13bd3eec3dc4f76b8