Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.2-debian-fips, 3.5.2-debian13-fips, 3.5.2-fips

Index digest:

sha256:b1fabbf4d880a86f6238229a6f2cbc38e0eb78583c27292ee6aa13b0d5a4ff32

Manifest digest:

sha256:ecf3911f5ac82bc00fcbcdbe8600c76d16993b5dff999cfbcd3eedfb96f022c7

Size

94.34 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:c33657b4ee1048cedf345f51a0429a33a93c4d0c7a4c0f1b1ae6dcc7e58247b0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:b6179ee35211a575c2bcb14087c29f52445ca96cb9cc75fe6565c685296e9173
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:4e38980e7d3a29558b2362449673451777110343ad7f649380a58b3191082935
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:54d3b273abfb80f9a31a32691463ea27c6f303b0de218daa74d1e2ccef279cc1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:a92a2e136833abbc506103ac81b3222a9b2cb0fafddb21645e8c60fbf140adf2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:686faea9c034e82a3371b07609a23e6b9a7e5545c62e479a64546a04fd8b7574
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:dbb1defb60c29017619c43a797bf1d87a34ce437e1cb20b0afd04c84c2711a4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:00920421658b1f7653f241decb387b4366205683ab79ba382e9e7165722f3eba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:5b96b29fb1ef0319a5ec09deedbe823f8c9a946cd529ef0872476dce36095bf7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:aa5ed22de8f0cf1145929926612068c1e08b1377bcf8dcfe9bf82f2e64732893
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:ddb7bbcbed0d5351e8253c0b33cafb079a04d4a94fc962fe883307a6b15a747a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:4debd6eece4d0ff58b53d5b5b85547535ed05e0a3ad8f191fc8b0d3f951a06a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:32c42a3538e71fb1f305b277167b1fc62072cb80e2e7cbd4689ae90a85dd66b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:390663635fafa4868468fcd4a6e11cea7b4fd14f545b79c16bc92193ecfdbfa0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:5694bcbefa60b4d04f4db61b19fa9d33d88c7cd1bfe89177a294193d6f360510
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:3b5899c68cc3fc317353ac8d16988b917e1470e3535cd9a8e66cfdfb6b4540ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:0572a02b25327e9393db784e29ae50252395d8c3c0e0571e2452687321f9bbe9