Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:f4619fe046569400a2e597a3f24da3cd7fc29f0497d6ae9d441f652a00030a03

Manifest digest:

sha256:b24888423fc3e5b3e417c90d7dff8212e7c572be9719a03b52c02313f5d7aa6e

Size

191.12 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:bb5eb175bb8751b1f4b14a8f4224867072b2241d4b98e4b5d8eb13913cdc137a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:e243da4c3b733cb7ccc2f85a6dbbe12b2fa4bab0e1d4b0da23145640424d09f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:64e234eeec1f61c56234d43f3ed357f247e2e0938060e2aa5f9eb353f10c9926
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:3663b116e245ddd0719e680c72e03b52dcee82a0c800e6e90af16bf86c6d218c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:1e81389aaeb957e4ad65bfd700f4cb26043cbd0c39eb102e9a40cc56fc44aad3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:d0c1027d2b50d1a7272021e5f0521ace7aa7e3db750ac9fc41c4b03d2ca80410
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:04089309b9a25cf1810c4f7bbb2e43da154cecc36c26946959eff9424d658d06
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:578651cfc2bd5c5fe8a2943870932c4b9949e2fddaf657ec24ec2d191b328f36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:7af39990e5db9da92e53f73b960e90e8df930900fe7f0d7055cb0db2c824aa25
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:b7aa85090171982048ac9d804bf7f23b2139866c78fef783cdd54f36a8a89a29
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:fb679b639b6816c3882e0d8ab116737574cf9ac78b9c0e92f6ec9ed89f9c7488
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:1935a5da074ea1229d1c159762de3ecc153f2d9acfaff8b055c1496587212d28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:e51dd8da7b35439b70eb9d9b8538694d90b738575cc8eae93c98e6efb436e07a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:ce50842f51784832b2159ba2219dc6e87a7a509382f465af5a86113697f1ff82
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:d7cd5d716b7e4b6cd09b28c3b23bff8fe7a459c0b2628f70e435fa9e04d3e579