Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.32-debian-fips, 8.0.32-debian13-fips, 8.0.32-fips

Index digest:

sha256:e6cba0b768c88a637a9b98eb9f4462562f939ad6fb6afad5c83c885ed81cb685

Manifest digest:

sha256:47555ae48018d4584b6dc237b319dbc5bc67b2e9088d6c0dc0cfa138f9134371

Size

63.87 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:306baad060804b20729ba4a420ab8c7cc7417e153ccd804b34194a762c9be0d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:7698da84aba99a2f5a03feb8720fe62a6300dd9b01683e1d62104ac8e26091d1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:048f88e39a1bdb0be84a3a28c79c8a53e89de12d339f57292784e304fcdd1b6c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:56bd4274b5188c0c8b7cafe587f96e9669df0ac4cf20c92ffe70d0e91d41540e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:70d5bf7ebad14ecb5a5e24fe26b3b5145007f9c51ef44e9948eada1828dd9526
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4937fb874f681e70acca2f6e1e8bb2cd9b0d8aacc907b3a5d18262d1bf7246b3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:23e102756169241439580715a0cc465c265f15aae54509e6009dd9ad5a2e9f61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:99ebfa6e353dc97e8509df028af7664e0b25745c246e1474315df4a4dbd02315
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:6fecf7a5d181806b8518d70b59eb402450a1847006099115e390fa7ff0f8f4aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:62a79c325a1ff303f56482f9700aeba5d2c13ae2777a7f533b592b921e0b25ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:e6434c0251cc9abc391affa7aea2bb1c8d59540382f47a0bb15f7377e9a2ed86
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:fb5cf4431a0387e372bee3d1eaa972d0b243220aba24370f4f068cfa3710408e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:f9bd5d503085cd885ff9b7b15a60c0daed02a0c579aa202eb4d50fdce48da6c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:c52b984a0418839ae835ea9e248d84577b44108208268fc9f14a2484c1038b91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:033178b036fe4d3022e03406167236af2c8111400ee2a22c17f7071efba32bf7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:9149890e576063903870602f0cf9ab7b3151fe7418ac04e72c555277d0d7c097
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:9fb54276576c34f8cd2726353378212400c5d44e4f61691140d35bdf721e2c82