Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips-dev, 8.0-debian13-fips-dev, 8.0-fips-dev, 8.0.32-debian-fips-dev, 8.0.32-debian13-fips-dev, 8.0.32-fips-dev

Index digest:

sha256:a33f5297da7b7f8dd7c532708906ce5a4d18ba9fc1d72d83e43559b9aa189991

Manifest digest:

sha256:7ceac584ea67357790eff40582868f743f482fba4dbb845a9be35ca9de7147f0

Size

191.93 MB

Last pushed

2 hours ago

Vulnerabilities

3
7
0
1
2

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:fd1b92d658fcf7897450861c7a54311d3a7c322f4153e2abe4a6d32b3ba16615
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:03c41f2520904d75b6e110c64e87273944853fa0703b9abbf7f210f10f7a9914
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:d0a5185f41c4bc5309a6f9e660afa110e160a8b362d5207c85ac3c312cb88df8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:0405518cbb5d3eeee4e204aa6bccfd8d903e0a953cbaf81192a67aa26f931a6b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:1cdaf0d3f01c6e424a33a454155951d58782347c11991317832ea70c8c4478f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:9bc86299f68d13643c9f9e178031deea846efae2523386857ce288247fb4f37d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:a105fc849d5adb1b88302f3d035edd007369523fd74eb563b66c85b07fa91949
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:c89b693e6ea5ece1e7b82eb54346112ae95f84a286f3720a1edae4c6674380d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:03363c586a2dbc261724170c237e78c4d118d7a9b3108a4a9ba9d8aa8ea5ed7c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:4359aebf27f66874d789fe1e17c563c1baf4d39329ea37334aed5c24895be1e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:338d9c5b918077b03ec342d0349e7a61c7225ed7f85de8095251953df34407bd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:d69f5cca7260cdd4eadfe4c6a7cb6d6d7f669d3556c3074b8e4da80e77e8cd7c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:2533a6dead32e99ab60b7863fb9acb2efeaad1955e9db07839524700782b51c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:463d56ae74f27439d08c2523a58fd4cc525123d5dfea0449e558ac3d2ec5ffd5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:21a170dbe1eed1f52528a062cc2d263c13249cba70fe70264c4171bfae8698fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:d17f12f72b99aff841eee23d4d606472f6e258b1af0d890ea683c831f37f0842
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:79cd1bb50b8038c5cbf79060c14bfb164624bbcbb7ad443d71145c1fd99f7cab