Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:fcffa4a003084d3f2dbfa2f305583b49268bba4746c71e52a82ee5b79865772f

Manifest digest:

sha256:4eb45e1487ec4b3fc29665b80db8f1192b4e31482cbce1a3384cda886b72a0d1

Size

185.72 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:ba69dad21610d30794d711f2db58a684898facc2ba11d4d493b665fd0a30c217
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:37396450c2dfd7cb923d540a182cd335b7939350fde5df096b3a3c72c4ac671c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:68d158c8ecbe9e04adae45959f60a4e9dcb1d8e72860c22fd37e8e6f04c80644
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:dda299b9d11370fd42b1ef1d0147ab987d569358356192da390eee2436fa4b88
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:612ee877bc30ed72266d3c241c66e5130928a6596f2c1d05b4895cd1ba2045b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:1f4eba8570367066868178e120a8e0617632924d439720194078901dbf43881a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:3e33d96313fb5f33b852bb8a0170f289be2c0a044b6f6eab524ed186a88a6923
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:8e09729ca36cf6bf3789fe2d4f32677f42260d00f8e96d1c372dea0d372eebe1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:c193d1114656591fc808921accf40c7894f4c8e6aa70502e6944d09da69d8fd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:5fe33a53529f077d0b214993dea79f3f5a29ed3e67bdd766aa5d65d055f8092f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:b91b73329aa62c8bc7cdf88870388226c741e24b5509be7f283421f60d869ed7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:025bedd738c23328af8a0000dd08bc3b2c95f6bd60c251d7b05898b1e326cf48
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:e063d577f4520c4db45d070cf8abf304cbf13eb5ae4f61d45e8168b34e42e205
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:28ad77ac9b8691faf7caa44b0bcf1b8c7c660561d37feaaf7c0ce81ecc83f738
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:d803fae5cb5a7d113e3edaaabc194357a88bd141665168be9ca8991a95903620
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:dea31221ca3962af90ef584b2e0fe79378f49b637b31e2de6061764512549d86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:aa0d47e9124b1cfce5fa21fdde0761c49d291e538478e5d3e2ec75f35a0db7e7