Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.11-debian-fips, 8.3.11-debian13-fips, 8.3.11-fips

Index digest:

sha256:fa237727590d01023eee50d73876c9fda7695dd9ee3207cdd39436c5f204adde

Manifest digest:

sha256:ac9d74fad6b984ab027f8186cdde4b7ebc09d3de5fd6f48ce9acbccffd6a908f

Size

57.72 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:defa1c7be6e016ef3b10ab042800122c6e61127c10e43e27835876eed9e6f54b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:f8f0c262c7632c11710b5d40d02ef35baa1d6ad42e3469bf712c20106627c716
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:f3b05696732db1ea3c4940dd6613b258085c1a2b0975dd0dbf77400508f85268
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:76f1ebbd4bcd8bc0cee14c1c961c1b11783a55360eaf80c31935b732b199a7c4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:0d686c1272e47f5767be69aded005ea1e19bff5549b3b5c7134c1bad4ec7b30a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:34bc8c53d1e896e3317b2d5a366527135e9b5178775828b29b92924fab079f78
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:f4bc80da1c9088f471f6d77a22b637a8e8069c3b5780ee75f438f87f2e258fb2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:a6b429c9c400b4788a3828cedb6e82180c473c6bdfe5f1da71c234e6594cfd03
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:2ae90243e39535f7b6d0383653b8f2cb4bcf455dae26103050b3fdece876f2d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:fb57eb66efe8c87df7214ad22f1ca110af03a41b4dee48957ee04b74cf24b37c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:6961f7fb9fa6045669da4ba4d8719a2c85caff28140dc112032d1cacbe69595e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:56d846defe23c6c269ca01af295379202be260612472f6d1ab2dfaaa6ce78f59
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:60dffb32402116abf5803a99dc342a76531b3db0cb391a4517fd63f3f5ed4cf7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:bcf8b6ad1a61384e1709308cb2bd5a03a02129f6d0d19465e2671e6468f56620
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:48ec7b777ba26523c8f327ca64d92a9c01d961fa44126a1f46ea361500dd948b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:70920ab3b4c2023daa9a45f59444014d4f47386541b7a6ecb5556c981e86b258
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:6163f865cd213cc68dc758149d37f777d43f606cc17aedecbcd9925d9685771f