Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:b939e2742896d28a8b31feb8d6153bd4b7d8d60957e75e0fbf2b6a43a525c74d

Manifest digest:

sha256:d910978096dbaa4b4d729e833772cdd093de086ac4e6aa2d909713b3af097b5a

Size

185.43 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:64dd09bf2a725518b48d2d351adc5f5bb1013a7cfdced8668e1baaaaa464ec55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1542154e8264ae78ee21042ac2105b783781ba12af5b625ee072aa3d022aeb9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:ed0894ac0d9b39b40993f1a553cae86b9e7fd055d07ce70c2301713bfeba859c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:26a72e05ea6ccc9b1d8fcd149b6675f1d34d74717508d3a1b681314c7c54d66c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:071fab4ae86e565b1f39ffd80b42d4e7d1daa4cc3d02fac85deb809fe4c5a287
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4e789ae2ce9d8981a70a844c4c4eb3a67544edd46632dfa11d08f43df55e8deb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:9913f2775765d2c8389422ea4cdd72da64ea15d7ed26723321bec7225c8cbcbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:630f19d3a21df750e57e2302f4d47e88d804c0fb0df6eab5edbe0bc1a05ebcf5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:013ba5bec810ef82492a05f2a183fff5577a96212def8bd5eea72bcc1decdadf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:bd718695cf10053cf2d17886bbf7ae43103bedff1d2c3e214ecb202a38b3ee62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:aa619d25c91e41ef7a6da9136169e8cf2d4b6b924f21342b55ec8dff64a10c3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:63f63ff17d3eadc2736807f9ae0962fec459a7290a2224cac8e0a4891c14d72a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:7e9d59ac91787d39738d6d200b3fa70d4664f3ba314625cd5eae7e9da540ef0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:d7f52e57009e32afd489602c773f6019f6fdb2f9ed772ba9bd53bab9979ec56e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:28294d95c62279a0949031c943f2b559282f3bd41f4a611cb1f16786eb647b9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:5140b85b669f7750aea4b4d64f5e349aa11acd7a716fef61017641511e47d821
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:8f122be8e6400cf61abd0d691185e73c63699af86ef87f20d3c95f9f9993bd05