Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:b701beb62eddcc45d11f16d91e2177033c59b753ca319eb0a1ac1e6fa8047a09

Manifest digest:

sha256:49be2b288a509c33c7c83683c727eaeaed57edc66cd9a5a17f3abda98d239518

Size

185.43 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:5877aa5f35b218e30be93ebd7e54f92415718d62e4e17cbae98465b7b54003ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:c42619cfc78b00eda6876ae301de328a86b2da94258a43135893c6d1307ec89b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:32ab5d4bea17ce639e94bc79bff9db5e34122fb43c3ea483429212e8ff3f3373
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:48604fdede539ef0f66493d09167e2f63989c426ccff1455a4f93a3102ae3eaf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:2dbe348de6c79154decae5229c3dcd96ce02447e51641854e65775e8c42cade5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:cd4cba4bfd7c4257a2f2922bd63aa94aaaaf3eafcaecd190ca38838655978aaf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7d77e815889ec003cb68ad80a43b473503b54191250cbf97738da93d8df2a128
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:56f551ea28e92cc9b709cc6f18d98322f9769f3102f2a25d84786e71466b4c71
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:3bb4628574a825481b6bde7e85dd853a3b51a4a9f483db8717216c534e4723ac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:ac58363b94068bb568c867359aebccb74c45181b7c2daf2f27d2a9e493fdadf2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:37e755596b052cea6d2aeb15dcaf7c3d80d593bfbbab7fc2f077226b5573c5d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:8e97a16a62e7bf520d82c1a576b2fe249fb8c97d37b596023fd82ee3b35ad922
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9e4f48dff99b5f4cbaf10abf0f32e8805169a40e28b861cedfcc7e8cdfc58a94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:4213ad745048fafc4c1a91aa8a97eb394a9991083802b64143c8c8145a3c75f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:46ad98994a01873340f435269ce50d7e51ac6e4f60f5784cc299d28e92eb1c63
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:2ac1428606bb1fe1e5909017a0b67caa495c683aa846d0e3d2b9699b90bfab99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:fdaa1537b5283b7421c137405bb4f9c4b5ecebf6b883caca6801da60cabebc4c