Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.32-debian-fips, 8.0.32-debian13-fips, 8.0.32-fips

Index digest:

sha256:8a031ccca88f21f511c10d41728359a5f042ca8fb40a2d05cefa3b53085cb5c4

Manifest digest:

sha256:485d8e5eec9072865e3875eebf1f926d8a586afede235ebdbb59bbff392edd85

Size

63.87 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:587a7b66ce04c61132650d3e316fb753342cf3306cec3e8c5ae62110d14ca943
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:21a39f76362c14a894121ddaea2e4fee99a3c485202262a55db07413191d64f3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:b8b28d9543b9cebb3b4777db2d3c1a8bd202b264975044a3f336efd867647ddc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:c3cf61274264098492908a53ca98b52c1fb36b40f3ae40f029dc4d8f3b99c2c3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:e12ce72c35f69dd2c881f0e57b9f7cb612f29a4fe3417ebba604c83dffca3a43
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:98858302642c3fa6f36c119db6ebfdbacb22c328cdad8bd64480d65427ad7142
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:f0e0f51d31de3f5659627fc2e203a5b6ef37bf1ed42fc11b4f6a3de14a98fe43
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:136b59940b59e2ca3cc47a200115a7ec631f3ecce705ee03c5bba4ef7d05ac78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:5fcf153725a68d05c6754d80a3ba5e806036e412c4a8d15619d0291fa6b321b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:f49527dc59a13bf49066a6d6d113ac4ad9cc710d446dbbd0008e0d8d23dac8f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:c3fdce312c9a676178d9b9a2b90e33c0d4154669ac16bc2f0ae8a6efdee9c0ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:447d7f1d4dbe66d2b51b6a56f8d10b70a6ccff757d6cf2678e772c9bdd9f338e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:8f2cb6d488c62ee745b3a96033872e564c28d2bd844eceeca4ca5e3a2d221212
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:9d7b09d0b96c44319eb63a430f05a8c93eea694d8b41aaccddf7ec088409b9d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:eddd01f053c5ad78cbc4bd4bea1ab3faba7f0aec022e337af015066f822063d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:d520dca249beb0fab13c159c3e956c08600403dc138045fe7c4f16ed15dece2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:1f747c102041e0679f57bc7f1aa14d04c89638ffb138c37b270a828d4269b41d