Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:fcbee9617bc70c5561ea47d25059d2cbbd9db936e400dcea377fb3334fd5287f

Manifest digest:

sha256:4910461e1171d11b7dca4e193df66fe3dbe253d3a08481d7c1acfc41c511bd96

Size

103.95 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:fa3c6a0d18b31028b3f52a643d716e665d556c618dd6ff5d5585133b254e9ad0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:6a60043b6fea37a89c494e4ffde154080d472e1a0f9bbbe3a7b111a81573eb95
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:76c311318070bba2607064d601c7924e957c3b39619c4bae27b0106e814194b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:5136fbcc44987b7e99bd280150e3cb92b8ff233196e258b122c21b47d3e0dde7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:b773bb73696ba11d47efb123cb4d5a5a66007bc8f86b2ae41636b411aabb0edd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:9f694b936754f777e390f312c130d3d342857b17822c1124f6a860632d885489
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:13e9690f4a312c6117ba4ab73f69b7f85870eb7987fa2cfd21ecb3a27e9298a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:d829c122d78dafbde731e68145eca92ec0543d7fcb978b831135a5e8ae5562b8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:3277c584cf55d29820df5835e47847ca0a9ffb5c2663c51a402f6057a6ebd9ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:abbbf02f5c805fb1242cb82d6a6c1a932099bf34c7edb8a2ebe5a81e652c34bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:eae65016f5e4080ef50676c6525d835f034c5205a5796b1fb108bb5bbadafd66
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:8f9ad2a6b98e992f4eace77203cd3d0a4780b8d26353bb6cfbab6c9a63bf158e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:6952cbb53c624806cf2bedf69254d5f5300092a1db85b2bdce99056d9b8a21bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:bdfea11836745eac787c0c27e06841e13a3db35cda7802f539a23a05bd2d2d44
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:61d6d423a60304fc76c272b0f640a2035b84d63b47655fea8645e32305a4bf22
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:5066acb618df18a6443c0293229cafe5d1a65649e760ca334651741ae734bd83
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:754004849d14a035efb231a8aabde7483398adffd335c3a32a05075f3bc68c03