Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:38ab8d9f2c529f361a70d6c576cf8f83ea4395a3c6b78aae9dc76a982328b927

Manifest digest:

sha256:9e799a5175f04dbbad860d98f6c2bee775783bf35a82ec1f123355c858497ca7

Size

174.38 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:352e40d63103625a6eccfe74dfb24b4d0338baef8e24bb1fcaec11f0fb4ca157
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:5a2f29c5aeefcbc93b9325409f5bb1b10259891c370130d167452bd7db2a4061
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:c77a4c4b507738e43384981c652342a2618d607f280e53327abe27d37bf35934
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:5c31e38b0591fb6e48341c377d7808d2cf09c4527bc6169634cb60ee65f6103e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7c872594626b9a7a033cca353c11e1dbe891025a9971040aa4e5febdfcc557b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:c9782a25708261c96165458557ea372a8d420e439ccea4704b1a7715120f7045
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:7a24236fc4534c8e67bb67349317242f94d9ae918c76e9196cc93ca77d619c8c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:a42abf01562843c9cfc8e63190acc472f997f93a75080f2200f401b7b7b2436f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f153779e14015604421052ce29e8ae67eb9a53137b91d442cb52fe6b88d5635a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:05c6fadd83a83b518e8793246b6e70d878cbb512dac26ea786a507a98dbb6d13
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8b2cf00533a507d157bce2f31bec352dd38dc4b05c430c6fd4233f998e58cc7f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:9a2170a74ad076d2e0235a0be2bc12701d7e5dd612a70e7f926474e428370c25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:92b5ce58e41b00bc9cb9ced58e72d72942ec9a12dc6ecc3df30d6796c95b4381
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:be63cca7776a37122b602a556a084b7a3417f9f56903fee00a28b6b8b858f0b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a7c77618c99089396ec96bdbc419f93c4afd56b24361d9f1a104b743c5c30360