Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.3, 8.3-debian, 8.3-debian13, 8.3.11, 8.3.11-debian, 8.3.11-debian13

Index digest:

sha256:5ce270ce4072c576f8d9dde98c5ef1187d4a6db1e8ed859e84b3c97378a64bcc

Manifest digest:

sha256:e5944846eb4c7c000669744994dfbb7b70a979de39d22354a04a26965e0bc96b

Size

56.93 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:3c5681a5ba2844c662d5d1cb1c23a86fe3e26311914bacb627fed7e14754d147
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:65b2a8332ac8618435d636f24de41ead4dc868e66ff59167aeda057b411d5434
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:709975d5e3423da1d301ddbf6b18c05e05df0e4b426928d0aae5988269f97e73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:0f250175e7dadf73dc1b6b5cdf0d21fd76132859258b724070f0c11c1a6b3f30
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:210bac603dc44081d10cd9257509604bb3f0d0c1e8e2bbb9ea2094edb1658fa3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:47c0fbc50900d0f761630765b27a8a33b71587b205800e6c5b6afbe6f21866bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:fa8381ef572cc379809482af70f861ae3d1f389e658c1c1f1da0f9a1f4709fae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:fb0c78006403dfa260827dc6100e26450f9cbaa249fbb07624768917b6821370
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:b4533c4b5551fe72a45b3b9a7f503ec6f6b1cd95d2c09e7087c5bebd0e8a2a4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:290bfef422f119767c35a6c8139f1b1ca38df65387cc77ea4dd7c3a39db8a8f3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9c992f21c3e3bab30bc503ae57f870f36feddc7b770e5ceef805db08e9b305df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:beb297a2c4a5b8627210f6309be36f5fe2b1cf3456c875437fa871e8a902c73f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:d715f99efc875ef658555de5cf9a9a65e5a2031e35481840372437a403d47e83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:dfb23a72f442e1d09e2db3a94898346221ea0930e711757fb74638c39f7b4343
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:de76b6079a480733ac2f25106709f635be5d4730fc8090312baad2ed09584a1a