Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:cb6044d9c6b988efa7c685a96b367190a51e2fff9f9f4407e764787224b952f3

Manifest digest:

sha256:741263eeaf1c72b51e4de7fc09927d26f335812fbd7ba7df9fc54afd7245b523

Size

191.87 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:da4164089a8049fe8ea9aa0e60f30057a6520bc543cfb95081474349a10803f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:61b699345cca6e9c10e2138d3c7a211116428cc1658fd44b58f17019d7fb49c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:92aeb34310af8a53b402fc62c3ec9260eeb2508feb8df89defa533edecaa0ff6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:9c66cb2a004a3a46f2dcc0fc229bec8aaf21aedfdafc6649c29a88557e846122
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:411b7fe8bb5c16d2dd2fb07a12992c381a5609fb58c26e67ffd10baf8d21002c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:ccf8906afd9dea1ebd66c383a8735c44521fbca325c69651d6f17e28a2d74915
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:0ca5cbe4d8cffdc9d3175f64a39855eb516513dd02a8667145026ad201027158
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:a4fa40493e0d2bf2833ad62490d804acdc131d78364ec09810aabfdf0e6d0277
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:0a6c6dde2f988511e25a43c54b51c6670431cc7d34f7752056c292e0ddae85f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:dbfe8f32ef92a796e8ecadb61c7b7147cb74de20f5f1e5808acf5237d074dd1b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:55da55fa5b9b923a3dbbbd29ff0ed71aa7481721a81831db02bb148e3fac9603
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:2f69a6f44478501121253d23c9dd943a6f819ff53a7173b29b683512a1ede89f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5bcd831815f599271b4e0e32c432dfb04f07ccc6c5070dd5c367b94d9a0f0f2d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:89e9349ceedbb793574e2c431709aca178bec53e05e0e0aab91de393c17e435c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:7a562a1836f0982f09bdec911b351d4c2028f2dfaa6536d30c678b79434d78c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:1f2b8cf3c8e2fb73daf680d1760d10153824b2e0db3593e1894fbddceaf3d510
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:02b718f593a65ee0a58f6859e0fdbe5f7813bfb6a6d06c182ef1e5b5df05e8b3