Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.11-debian-fips, 8.3.11-debian13-fips, 8.3.11-fips

Index digest:

sha256:3aedd87a7a883df4162a266beeea6e0e98988db0e69a165e91d76e1c172b0aa8

Manifest digest:

sha256:7f8ad84ee170682121a7c26d399389583c6f8f98d6bd4271764b30ab042f3335

Size

57.72 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:44bb548b78cd9bee55d6ab045d15cbfb778db9cd1558b1d9f732ea46f442c6f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:2d7f2d8e72afe0de59132f5e1821361210eed7504055a72a50d8d52cf944e259
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:79280ecba76756dbfdc500c8067d913a53d10cb01ef4ab392960bc8f5f1c3fd9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:6a3ca7da953a6a78927dcd490b0c0dfd94f558af4f1e84ec250be8eb48ae227b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:b6444b4cabb110da06c7c59bb280c67f35bacd7e367b95dc601fb920c8f34491
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:a8b418b075596fe5ccfa8733472b5b58f57edc08caef25d8d3b6bb0496504f93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7c9403be431563de373d0a1f2caaee854c26cfb44dde7fa01475313f1c7c4e8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:f903a8b9b0d14449ac720687a939fb8fd27b8cc9da19c899736536c4836cae83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:e36cc0e61adcd74cd6a4aa4e2b1f93c469ee5124c4b56059f2e876a3e2af5c51
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:df573795655a052fbae541b701d0a03d77a9c75e9ec790b5a5585ab5b2ac62e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f265412b45362d0372f0a3d0307f5ec1db3546217ffb073f01606d4aebf39882
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:d0b0bdc53b3e4bf08b0cfd52d219bb018e7877da7dfc04a20d68be0fe500dae4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8c2fdb69c757fd9cfb2ee89e232446894537bcfd5d2ac6290991cd4c292da5be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:3cf0eab91f710215629a3a93c6c51fbefdd940aede8a8877c4e8c1a4ffb2e04e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:be5e7393ce3c04fbea15fe437453c60bd3005dd5e6388e1a87c73f6b404d2bc3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:48ca530a5ffa17477a4d3a2c5ce17777a6a925005fe4f10c9fca3cfcc3fb63e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:cdb21ee037f86cd378a5c8421ab70a825aa5591bdadfaca5a2a35d3a7e0aa656