Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:1734405e34d3203a393313087ce325d52de3229703c6200244eb2bb3fff78563

Manifest digest:

sha256:22ed55b859ca70152fbe49e0a3b9b7de411e58efee382fc3d53bf14602d7afb7

Size

191.87 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:425dcb0706bead08198bc2879a112732dd05ccd646cfb2346eb3005f57ac3ed1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:bb2643e2d3a469d15005d1a3c2d2305ab3d7ac335856b1e14836720dca2c6082
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:8c650e07865d7a56cd89e98d51e986e2c68ae13ffc5f31b8e24cf116569abc25
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:46902419c499cb1627719059764a56277c3aef6e7396fbe1c82a813194a74a20
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:ed0944553fe59038dcce43f159c16d3618b2870c7f6c4f921baf66d17f3800b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:2a79c59e4ceb26dfb00b2e11b5b4f9dae12ffbbddcf9145937a9013d7c38a4c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:1abdd92cfa9e8f0c8d34c2b075068de1f25773622540791b2094f74f7521734b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:8a05abadbaf0b69ad64badd4f8b794d5464f06fb299800afa753561b1da9b971
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:b8d694f89a66cd74b42fde2c27087537793cd26ac4b339de3c36d22df38ed10c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:3959646aac89f3d5de8fe8e82af914ae5f1af463caac4d73fd3b07c38e84b9cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:4e61cd4fe2f2bd3b143e75e85f7eadb36670ce1e5bfd8d31a8cdaa519cab013d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:b9844f90f55d3dd560c3f47ff3dff7ee272aaf2c4bf2b88259566bd03b58e1d0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:bba916811ed71507f4ff0b4e08529a7a0741865ddcc253b262a30a414ef0e469
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:2ac4b67b3d11ff67a5c4186ed75f410ac226ed8cae166804b0aa4612289ddcdd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:aca532c56246ea1645ea4cba2adbf26009a60dde78fc95914d0849f36c773a68
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:575dfaf0587046fd6eebd6b85e16a0da3f2ddbab6a93a60e059c5a895d9a244f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:35252e8ec56d959824b77ce7086cd5193f5675f5fc96ed4e0a9b806c50a9a038