Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:60334ccdf6200eeadb5afec9d8726e7897548a7996f227fcb3f508667ef6fda5

Manifest digest:

sha256:a243ef04cec34466ac359a0bca9e8cb0de05aafb56059b9ae4b81f68ce79cfc2

Size

180.75 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:a2ac6df2a5227b9e2a114f2b1171459cf2b722bbda81f12e7bb6dcab9703eaa5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:a324db480f017abdba91564071ead7e478d25e0245088f171acda45e98a464a0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:574c9df398243a6ddbb4f54e61e9a05e70e3db53e6fe17b73fd4c612716e3bc9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:6e6b651c6cd91a7d006ca680fd573632dd0560dbb84b1a9af048ac431766b8b9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:c9610a82d461db6f93d21747cc2669033a05d9afb9336d0cad616d5203565842
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:b1d13a6d4fb17d451f53a549bd2fbbd494f95e44892c789e75f70c4a463a8e4a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:0618a04836488cf114613d7f27d13a674afdbd63ed36c85c6a5765062af89df6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:d9dc466cc4cdd9fd45e6c6509ff1d32fa0f3e9142b9a8d63fb82d0ac6ced7b1d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:57389bd86a65b31efaa180436c0411189868c422baaf57a27da74282c47edf40
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:39c2c10088a4e6e1830f96685a676b3979efd3907a2098d6994a00b827f388c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8d786baf002bde71bc9c465569006513b19481dc23c3b84570fed4abc44c45de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:3110c367458abe9e9bd90a0f526721338009ac5ecca8a6655d447dd2e8deeecd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:74a5ef7a0391b5545a93d0934c3dbe570d8c09756328b3f644ce5afcfb9a5c48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:169a8f7f0919c3da07e2913835e26eb867157a7a3b42b772437699a6a5fba87a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:0802e07cdac258fab318869170d0b253429d134ab628a8f90b72b2d27c268570