Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:09fa8d2a9c083dddfcc390e154c1bcfa33f7976065adb8773a9902323c74649b

Manifest digest:

sha256:4b3e5d65c635646743cbfa3e569088f23db6479fd1a514cefb2d974585e9ef05

Size

185.73 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:fd715b4b9135f408d8cbacd7a11cde62ca45e9d35b8a7b7f36900ab7a88b367c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1cfb44c016f152ae6e2ee63eafeb94a2dad3d291e30914f2ad9fd6840065a00e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:8ff1abcc094880aad68b10e1948eead7279c3db890aa5dc30a0c103b18d028a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:e839cadf6e28a3eb719a97bc6ee7866683e07998e9cc716e83fa872c2759892a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:b31e0bddda520a2be8c4c6456f132754552526a723ace626b80adb7ef4fbc4eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:6602ccc316e80990cc761fbc3885ebd66af944d1364fb75feb6a0140bf03b56f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:8f3212ac672f9f32695a89074493ff1b738155d4b211505a19eff318bb2bd0b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:72902ceda6e8e63c4005be13b05ec5a05c778036ef95dc81286dbb84da0cea13
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:fc3d89591a6070537fa530d0f004830a32f2bcb5f0f6f3f6d04f71483e357d63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:8073f929113445ee1517d86a6a1c723b5ec80fd7013ea5d1c913d9a8cf3dfe5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:b38b0d80cb6ff6b3d085d1788710eeb47e1c6aaf96b64eedb43026341d80c13b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:e32782d7564b01c4167dca42ddba62adb1515c934087f8de6448082c6181413f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:08b30194bd42eab8d71c7b38bdba8923b0877b7c4fa0428e2e4989bf3e600744
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:8752975ab303d1e4cf56ddb8ea83766d85ec8fc5083bee909d26cedfa142c032
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:2d16e409cbc696ee6a28cbd12632d74435b0c4be4be2e2c72cc07274a77e1601
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:c902d91db6ef8b95593c4d9d01f2657f8f75b5696f19be461139c8925d28491f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:6b2cadaed32fdded52cf02aa93d9a19ccf3a055c10880bf24f4da888f4a52d03