Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:d7d1ee1f1a81cbb06ea1a1566258d660048c0a40748223d63a74316f40bc8b94

Manifest digest:

sha256:7a68ef617ee2cfdc46083aaf37371e31bfff08192b07c929b8dde29b974e7527

Size

180.75 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:475b591cbacf39f15b24db2dbe02c68fa1cfd75384c5befe72c6c64b7a8868f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:cad0f51e2d11327ff659e128b1ff5a5954748571569793fc691fbe22db951f30
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:13496a42dd9df56f5759123d5ad4fb2f5da2a46539c5e8a82a1e8edcbe005997
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:959afbdc0e1012c7c837b00a01f40b01c4f4e01838262d593f0e22e93a1a30a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:ba2cc5c822b01f3c743954a07fff4f551543b20f1183ab0d1d5235f46158cffd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:caf1ffd588bd3a48dfb725ecc0f63d542d3b42ec57a76383db09147b084826d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:e7d1ad1d660df1f61a7d9b7238532637ffa43b1ae5f55a8287290477aac28158
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:0925c5ff7d9f7f70c807a54921bd4acdb0338f91b0309e8d35546cd1be899acd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f1433a40753931f65bab5412be7bbdcd4dc9f1435cc9f11bfbfcff1108677f60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:593314ecf2e50d383a57265462d8dbfbc9a7297f0e6d08c35515ec9600199228
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:ab3dca032f8a02a46c992dec85e54fba224227432817d6373b8e92ecd5e0cb4f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:524530f17b6d77a76b7546c97ca32a6a8772bd0d66ce00fd65f767e90274667f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:c0ea28f1fe49616e67e8291864dd7aa14c52f7e6e7b7a3ef4b1d9f14d6c0ea1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:988f08c384d28f19913e346a0a4dbf30a3fb128a17274a57be0906af9846cb5a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:70902db978fb45eb751481678a4077042156c64771c22d695063c9ec65bd7147