Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:c32d656feed3c5e02beae2a14626aa6cf52dcf0563f368e9d7c47212b3fe35f7

Manifest digest:

sha256:bfc057bb858412496c7e007431f07dbe6e190e7974f1c365823d8e7a1bf5c3e9

Size

191.57 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:c1108113004eb365efce7d2f7ec877f840ffbebcbe76e5f1154ec001a0e5c48a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:9a278ea5be17f6ea2ac097d292f2f165e7949c36c21fc72e4fabaa788592a5fe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:d5b04ac29a057b86384becf17a9cff604ae1cdf7122398b20167ff7306aa47b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:1510c48ca10c5492453f3ea40b9b5500044eb7fd9bf66219c53970638746c6cf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:2bf32521640283c417f90e2aca31b48a7dd825c7948ed2d7807f751092c5c696
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:22a58dbfee5daa8ff620066bf397a06db573e671c78c76631f2077cfa8fb0e4a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:19a689bcad388658bc8e41deeea3b5b39ca33a619406385a03b45042db451a87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:157967d5e92d3ab04cfbb301ef25fecaad2c5208f9232c72a389215d30ea57fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:77b5d48f27ba736842d6a4e2c941b61f6bc370dcc7071f52cc9332ac44673e87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:f4980c0f1113ebb80b138b6ae82069cf36a620b6cb2d9448500a2e4d746acbf0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:a334e75bc9f9972e669f65e4cb67256de1e9d605078ebff7e192e402f520bcb1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:825f0276ecc29065d433d6258cf8be5e90b9e16af15580a891af9b927b612d1e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8b6617bfb4583a8238cf7b315b7c5af8e92a6c80942baa56d514869316681e83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:9deeb9a1391da1dced9f3ea9f7cd24b8cb9f06c5fe47e6a6aa13c6717a449e98
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:b83f37985357ac3b1478932c8152a9ea0dfbb64e5d738e7d2972208bd3c3741e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:80fb5bc503315aff95211e9ec81d86fee7c5bea5f5bec7310314e8238693fa48
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:d7f74d2b0064abccdb346cbc1793ad00a045fbf03f224f825a4bda9e36721a03