Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips-dev, 3.4-debian13-fips-dev, 3.4-fips-dev, 3.4.3-debian-fips-dev, 3.4.3-debian13-fips-dev, 3.4.3-fips-dev

Index digest:

sha256:b5e4372c60fbce9a7c6be349357c7ad6b5f20d0e00056ad3073bc140408e20c5

Manifest digest:

sha256:36f3c2b82cc63080cd205c4a00137274136abb64c84650888b16e8a55ec5f1be

Size

101.82 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:d5ae4408fd98f1429ad3e20af341d088415d406e51f00048914c011158ef715f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:ae3f35699e82f0fb4443ee8b46654cac5d11ff9fefdf23c3297d18b08cb20581
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:45090dc8b6c3bef4d8bc4c7c08a6a6ef1f9ae0fb0ced4800ef448beae2ad7a51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:4b14cc418cd9bb60d074b58ae3375365ef397b90748a2cdc02cd4c55b5416dfd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:eaf44a7e492ba09c70179ad1327625594efbfc61777fb07b715e48252ad831c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:c390fd5694100c50efdccc8c251cddc960ed65b61682d3b1a799c6fde7adfae8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:6f4a7db9b96b191f94b9d32cac5356695066f767e76ba6ca6970929a6bd881ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:10dd01f26d8f2711d9b62ac8ba03a572a7d2052902088e2a30110bf039ce8c82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:0819bfd769762f14e4d1133a33b44733fd3743b2e5ee5a6930f4fc290df49870
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:18f7f9fe400d0cb323df4820f4db78bc412738bf86701772ba9e9726ac78dca7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:7b375d18cca5c4d601b8483bd3961dfe80592584e561e49aa4bf690d87daaa8a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:44187f5822d4e67000535dff4e8c5ceb78854730f055cf40f6e50baad30aba7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:0648f24da3b5092246dc972fe950dff643abe1ae80f71117e57571ee464598f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:a6835a9e7114f67ad66c32e68caf4a6e2e0c078b9b11328209883e2b0a2c0a07
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:f0d79592e9fadb2e6a6f23aeac4622e648809f9c335d0566b274d975f4024faf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:575f9f587fc37b1fc46b5492ba0e4f0520225132a27709afd003085eca8ed205
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:366e00a2e86d8a17c826863a0c84cd4ff28e7246ade0ba1908ddb5a09d206756