Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:bf8652915f631a084f1e2bd67909f373cab50960663b75f17d0528821b9066c5

Manifest digest:

sha256:94060a59a1c11cef483fbe41732431467d60b64e23c17866cd2056970f8c9b5f

Size

191.57 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:9515825966b5d12194f917a72cf6553ebdda0a93eb7bdd920d8c39fb6c74f889
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:4233b33df8ae3d7a88d682704f93d71cbedfe18af098d4f214ef7c17d59cf50d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:d03df226940c60493dad92efaa24da87de6185e09b57f59224a7ee7a90184bfc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:115d2d401f6e9756ca3b05ca46a825892cf9faa4665c49a99029068e8a731f12
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:48436d6fff8cada11250626bdf22e885791d0dddb3459963ae4d34b16672c67e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:dce8d34878ee98dc98d5e7f4299a8c3cbab178b0d3af869250e97af6cc27f817
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:40410acceae4696727e85fb7ec01eee94353ed19ae4c02f970901b5ef27e397d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:602f74037c87230b2f0926700f11b1878932de245b21856f8783ca6e6b55378c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:fb9005892963a8b9252f02892f89cd6f38b696f90393c25c885ab90989d2bfc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:965d7a01b5dc112c179c14a0f82b112224b5c7939c190fa6956f99ad79da636f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:15ff5042425204691f334f87d11c3b8e49e2fbc76208a540cdc2d935fa7e398b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:a5a9d86f8debbc054b8e3a9958151655e5c7d5276a49f38f921267e2bb9ccd8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:47062bfd83d3466eac80a7f298d86dedbc6b48402603b941577c5133ac87d266
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:6e49947a6a321a83f6844726533ba4266dd38f8798aacd7e28718cd724f10a05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:80d562b842e6a4a05637c6cc00f435a9df46561cb86a392d26dc7bb6d1f1a86a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:143f961ba1bc41413452c2316773d87564aa032ead81ddd38d69f83b535945db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a9de2a6264925510e4cc6bc1abb5f3139a97b480c9bbe870bc3a1b03b0509e2e