Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:9f3ff6cb536a9b554010ce3fa07bf570602962225ecca91525d059d47134b47c

Manifest digest:

sha256:41f6ab746373971b58cb5d071c377c5ac4f8b00dbf675a80fa43ecc1dfec7e00

Size

185.73 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:3332b021890d448a1fee840363a516436e44961fd211f154e51eed8e930d50ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:b3ac22625a69e584b715557ef3191acf845ca743b37c559fd3a9cfe9f6a39cf3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:aba7803d2ff1edd6f4a501b959393b97487dc88045ff12333170e149bd5ef1a3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:f289493cc35838d8f9b44cd646bc62a71c232fe3e4dd0053c1e6802c414c7bb7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:65a4ef4a780a5e8830d94126a88fe0df49efb876e4549903729362261c46b44d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4396cf1f94672ecdee1ce9110f082f5a61f62229b3e85218e3887c156413f92a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:799e675c0af6276ba6c8ac2a427226e6ace1ac95139bea8e4bfbff9b4edca066
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:63acc7f04a7c2dd5fbc9f58b0bf33c2e8863c7fd97680bdd398fb47269aaa037
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:89755f3f40d58b617814dce204b644c38aaee2bc5fef1da58c6324d266af886d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:8ad2124b7e5618db461e5fde9679c9666b6e2d7b806182a6ccd53240bec19d17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:838b471735c85278065b99911845d959a9b265f81424de2da64bf6de6ad850ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:07856bbd01f936a6b7060adc99dabb5a6249594f1958511b55944120d4ea4648
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5e20c74185ac65aca63f328791cd2122358b235683a0ce593f195bdb0c7ba733
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:b8a88ac8c17dc506b6d2d85fa96ee539533298ee865efbbc1aa1a69c301f02a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:1695fbb4fca50d5e900a079c916ea5075259203cf5fb133fb08978adedb361cb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:c87e634c94d76868886e39c71de27b78bcb9b246ea7887e1125c4a2e7e3e196f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:9e04284d26225242b4d2d70b8f9100af88b91504f0f93cd58357cbf0d5442add