Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:6299cbd514ab74a3acb706abf230f4b54a57c1a3f5dfc0c7e8cbc57669afb4bc

Manifest digest:

sha256:bf4c15760a286067f0b19d7ae782eeefe3120bdeb0e31d4500372fcc06002c90

Size

191.12 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:19b3265b72c77fa30216af039dfd8932973a91735b3489cc7938a42917a714cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:22f8db35f8ee6bec0edd36e24a7fba477fa2269325d056251060723a183f0519
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:1419aaa1809bf7be542e6f60d2e8484b236978f55b3eb2103db8b8c7f758f4ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:1a0f9f94cf4d1f110c5684f72f5783e31295dbc15c837a5af0535854ee6bd6c9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:0988f6f638a583b3e15e72adbe2c386918e1aba037da80047a1cbd1b9ffe0b20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:c8f1ac3d51ba8ae4234f44b3bd1a7332814c637707e760a82cea98e7e2b8c6d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:0215eb822e4d0de02489947d22eb7e453757034a92c588d45130bfeaf32a3876
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:513d014b736717810afee6d74f3b20e6d8579f7c41afd12278fec135591f4f89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:b12b8dc4b502a6bf74c59056c5f4f25b1ced39a8a39eb11f0d5b1661923999fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:4913d0a85070904ba1995b08fa5336d11236c199d82c99580e126b824361288a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9efbe3879833905883c960c9656c602c423e716ec536202f9c4f5157b364b377
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:9e118bb59c21fed59ce882d712f4134df797eeb7236769ff93f6a2b295d7d97e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:d43d4351bd8f0147c89cf133f760be8990fc0916a65fa7b5bdee108dfff79a97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:fc81835b3f21ac5b515cedb80a0aa1452fb852918d52ba2b5c456fd205ba5485
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:21d362824b09d8f103fada6a8466c0510db65e924b9992d170d55dd3a38c95d7