Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:fde17f0525d59383714261571636e412aecc18ff3162a6e5e0819471b434d38f

Manifest digest:

sha256:a408f1fc1d4ea5f4de972b680c28062329fc1ed80e90381a0536da6f64dd510d

Size

184.67 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:cedc38bbf8077687dc24dffc94ccf4457e8319a6592e8660ea389587eebd538e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:47b94a12b7b3095ddac857bfaf08379aed873da43a6a8b801c8596d54fbd8247
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:b837807f18eaec1a0fe223b3d8dfe9c23c59252bdbb03fcbb545d733cdc69f0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:316debb7a35d5c0ac18834127dea8e8bb1695ad68fbe319659e9efcf1c47a2b9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:863ad7f11fd872233e8dfc6cdd3bd816934d41313b5ff5e7b03542ab25d8e0d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:e49a424fa5bb1709c985d3fdced6189b52b985585fdd482de8ee0b819166d122
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:57a875581f67055553c7ac221cf9c132d42571d08520e230e189e956c10facb7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:c9019ec1f8cc16010214b4da833cc28c8de25ab2ce21c2600f705b8a4fcfe53b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:8fd24c9ce6c37720a2ade3729fd6e1d9bd16ed9433b43150a7e085c041b683ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:688f3374e41308d5c18c4d6d1ed6f3f1bb7d70bf5ca72fdc06e1e2f5ce836bc8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:7f8058cc6a3249eb2904738ef64aec9b56a0fbc67d414aedb044c784b12c45c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:49c1ce1dadf8d007c69983c44973992723fef92fb1a3cfda16d2151b69f0be1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:51c8e29d1f46a10f86a79696102dbf1aedbf220a0569f2a506fb189836cb0faa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:f9c79bb7b242770340e8f966c39e3e5fdcebc81f599b60ba8a1ac15c0158a141
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:07a96eee8258cda7f71fdb37f42f964e3093ec264866bbf26b6711f7be4ae8e0