Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:f33d3fdb5ec1b987465d4dc31d410e0c19719d1570cb965488a39b48fe3d68f7

Manifest digest:

sha256:f6cb1804ba5280a7477c015d63b4cb0c6a5c011ac4575a8c62ef5bb5281cba8f

Size

191.12 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:1f3a5fbd6adfcb03af26afb3565559bcf3bd5db6d3e5c0b0511a5a72c76761a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:81abae3eb88b05dff383e3c1567573207140d8a62faa56f0bf1867a38c2978dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:d6384cf5ea3524c48f4661a84d84a00c406f4e9e28723c3fae6b2e8c9b57bad3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:fb35eee3e59c791b82575f645d2d7f2574308d23b498134d7a0131a373646f6c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:b7fd8f803bf6802d950a3656d14ea2d565b881e660fb32b77cb568aad48e8e9a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:e514d9c9758c45fc9e79c31519e5d15de0af54259e63eb272b3ec14a9e0bdcef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:0e59563fe5d85d0b5241cefe8c3daa86c99bb8ce5696f1051b5ee2d96052f05a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:b4d06c7253e6d2e00b0e5d91217684fcd69f3fe16352d49d71b1301bb5df6bbb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:d143a91941838d39e5721f8ec953c55aa6cdd0bb4414143b451c9b38862b7c72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:baa404b9c808758d06c881e72dcc84b92d94ea3df6c28fa34b90a97194f709c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:2ad748b02ae7af26679313e40bf4c16dc467e469fad21fe199fcd9aa04561be4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:d10d6eb7e17773ce3b04630b700e6e0935988f8a8b4df11315bfac186737df47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:c348d2686ac8c428f0751ac3c1abf507376b613c3f5f9bca17af942f04c53288
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:63a5968275b4a93c04f9ff45ca6076d2252a317f10117b5b3ebf388387dba175
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:cac85902d6b1128a74f68ee4a541f57e57b624e5c885a2099ae782dd0043c023