Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:827013954b4857f85f3d60835c65b5122c15278535f5b005a1a2486486871539

Manifest digest:

sha256:9d651a2a4ae3c395f21f058db75f77bfaa4ceaeb434cd4e6b790283c26982644

Size

191.12 MB

Last pushed

21 hours ago

Vulnerabilities

0
2
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:8bfadd5e7be543234c39e3902f1dcaed63c038441be4eab8fb03b515ffa4f529
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:905f2da0c897777efd8f6bcfa6260c469dc5c2880fa9286919032637153413f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:b8c565407fa9ce384326a68f0df634699fd2ded43c171263696677ec6195d5ab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:1e1eaf6192b88959edd3ad487e9c2cec6c2e6e2915d25eb13dd7c2b82d800a44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:a5f845229b94b6286b2c4346bad3412e08b6e72a7b6e384cec797e6e7388fcfa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:938a94a09d75a647fd0bab023406e8b38af7c409558cc5d5487a38da541b0270
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:bc4ca7ae223aee6636a3dcdaf0365873aa28bd73948eb7a6eda62614be649423
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:dd7586dd4ca64c019f3d65af6aeedd5cdc28685a7f4e845acc4ba2cb5b1150d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:dbff26be60c1e68db8bc735506a1a065c692cdcb852fd930ec970b73d2755655
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:40f082b7dc74f6d7e8d152956496e98402d6597abf42fe25703912b6e601b8f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:11fe94d11076493ace963cd6536c21e8fa77b220f766acb6250e65c739eb7533
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:41334b9c0c170084f3ee489a6f030501930a57f2ecac456be08f365aa6ce2775
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:8becc7233ae51fe82b4a5ac2e15055cb935ed6a5ec0838d705de01b6f9d8f221
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:61273a8dd2ed0726ae1c20ca4f5a8312ec33ad52e36bd5e452fd06336e9ab332
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:959ded55a9d44393e2ce405a4d7ba7445f4b2b8841e492b76a93535f4467d4df