Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:7a69ae8a7247a79a3b3c145a2808a48877bce3dcafbfc985c75b677b039ffdbf

Manifest digest:

sha256:75a1807153a82f2456003a8c0e643239618073d2a0f08888ba4949d824c4380c

Size

63.12 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:5f6b42e520e771512aa157b5301c275868a293b75c5ee737f4f5a7f55c017f50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:184cd4ec9f6f0d719785d3c37f79c12b1c4fd1bc40f18ab1617517ff2abb27be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:c7a240b7c18abf128184d7b79d073e041c43f558dc35f4455c560b9bde04c12e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:c17bfec7cb4211eccdea1b2328bcd6e937d4de53fde5412274b1510f81fbfa89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:cb0a607809165d23286856a6d927839957be283475a67aa783dd8a48f5f64b39
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:805cfa3d60b4307b853917bbc909e1bdb0672ee2eb4afe5d5691ac78ce27a2d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:a5a05593cc4ecdb40cca1d14c72aaa98d464b71add2a60b53e4c1b65cbc3beea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:eb225568d7d826f6742d1eb9c282db40e52983ad73230fdeeb8d707789593edb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:9fda356c8066e5707c283f588f2e68161847f430d207656944647f39608c5df0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:6ece06afaa2bd3842323200a6c7545e042bc1a425cdfb6bc29b60f3b7ab214d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:d4d1f029d8f61b8427e9ef61b6b49d186f759833eb139881311ee6a9b89f4a6e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:cbe55743e5082f8aaeae443bf136eb341fa347a14b623b59669aeecaf8f05caf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:e0e5cc14eb6ff016170d3d6219295f1d2d57c48da95b618ca7a81bf2291b24f2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:5c11eb2d9b22e65e5d9c84d37c62603c16730e436cd92d7ba4e0adbdd36d29b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:c949dca889115932f46d7970f0fc2211e9767fad58028a770c57d54580ca9b3f