Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:e0c63f6b583b088f6cbf5c290a22481520f974364d908f256298337c9c821e20

Manifest digest:

sha256:fbb6d614c869a389c891cffc5afa047b8dfed8d9e74a4fe27d8f43627989ca41

Size

190.82 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:d87d0817156da0581b46437c4d05c42bddb56addc94fa85e282ec5cd49aa1a91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:12fc390f8554d8bab0fe82253d04842379150f9d0cd3c3da2f6d89f381fc1ca1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:279e30507f736d6c2c6c62bd22d0fdc40af29873a2252b613b3e91cea50e6412
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:92aeb7469a6c86edd89ded144f23b3455f406f3a116c3d6b03c79f03fa371b02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7708590de5552db3c95f4c3829315b0cc4e8348eba701a61c81e5996643b7dcf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:0d5ddddd9e9ee5eb6ab3bb51498ce44935236a1f8d0798d19ba799fb3d0ea061
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:4e0010d4702c2bb243e1aaa5144cb727f4cb3b0e7dbe7c1f083eed2b3175e980
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:1a6fe7b8ca8c9a56a240d05a4b5c04903de8c23ede901b7f0e9e5b403136766e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:c3326a84667f08298012cbe4494bde8b5964197b1edbb85b47b3c4e15ed29218
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:e2a2837d02e00e591f5e7257a454b5328cf8f27e2758510fef65ca4d7765f55d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:6794bf88ee5e4b53e2f3bfdf779f29a622db33da200be0d2a37ed6d12781e28e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:2bb46dea08d3ddfd721f2ec98b41b928dcb64f4e75785aa7d4eef1a529441023
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:2618f4273b3992facd68119793f0817023eba69a2c233fe8216b0b9e2e06ccf3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:c93bec0f53ec3d64ef07aff2fe841e2e4466f382c542a3d6c74caea5d753cefa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:f6d83337a78f4ec296c768b35bab8cb56fe49cf0bacc35c314e971fd432b7da2