Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.3-debian-fips-dev, 3.4.3-debian13-fips-dev, 3.4.3-fips-dev

Index digest:

sha256:def642c495e3a8b64c6fa647ba6e49ff7a67764756ef779a6d2fafedd66f47a3

Manifest digest:

sha256:0e3d4aec4af07ac7a031ceed3ebea1964e41bdbf63f6b13fe9b40026ef501c72

Size

101.82 MB

Last pushed

1 day ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:a5e9cbf51a5388a144d2b9f3d27a684fd63008c2803eb6dedb3a4be2727baaac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:2d38a33eaec4c5ac5dcc356644926ce469bc958cc5d66343f719e41aed1ff19f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:3deeef9161e63b3d7ce1cb0b2bc1929d454f942e90162be5910396e9d3fae888
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:b965f88883166e8deb8a6dc5e44ff7a747561f754e508eb6ef545c245b164af1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:189ec96b231f364c21f6101bfa5d77a8890b575b8f08ccd4eed3829422569045
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:93540fa5e08eccf82d953089644fe3d4f8051cd9a676c3c7601cbf961b6924c5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:0cc17409f1b65ad5f70caf93ea2bcf844d76994d522bb50abb1f036eb7330a35
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:7d72abfc2cc8654f99d2be222661a67987c478f2b8ea1b524879a158d625471a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:de5e9c086353635543f779f330fcb0b628e69a9281e611ecc8a7c4181a17d7f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:670151807db4d81077db570e8a8db356381833c4865c3f01b92cae4bdee76bf4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:bbb86afbf621541fe6845fa9b06200952a43be0d0d9f37e0f3625ce8f5342416
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:8d78168c4249052a4d1df1df7b3333295186ef592f622d54d848419a5a0e89ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:97228a45cb89ed18d62eccbae2b5e4971245345ab38a4b3d71710d1746c2e95a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:8d7f011b52192eecd53fcdb71e0ae0fad5e57b767df0367e1ceef0f59eec1b4d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:fbaa5ed530bed97630378733dedae05af7d615617fd1a28fc5940c3cb4b0871d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:d7a617748ff9d66ee519783d7bef7e54dc3d91a46ae89eaea6c3c8a5b9f1518a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:81282ad6d342e78695d2c27edafec243af70c0f04d33654c4a21db1cdc0dfd87