Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:89afd617899892380b14e46a0cc4eb9d482db74b56ef9f01ca2daaff51efe305

Manifest digest:

sha256:0898491f378edf0a3ddb025eb40a69811f588a68e7ff0863e6cca9becc06a048

Size

63.13 MB

Last pushed

7 hours ago

Vulnerabilities

2
4
0
0
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:f2ec2fb9494e4c5e42ca092b98655bd65421797077bcd954c093d3e6075b6bc7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:e3b08b8b15ad8c133b1695b583d70c7aeee32add9bc527041f408079173059ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:9c79c8ca95ac7c01a1c573a349ddcff12ad4e35f9d5571d8e7d8866a9ef7989c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:7169ec943cf2a2256e0c4f85db43223a2c3f197a94ad16bc93e58fe85b00395b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:76e0dd278dbf666b0fdab4be5edb5e0133d1236d303fc6b23d5493d6a6793ec5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:fdaabce4216682c3ef49cf0f5b593ec6de1222f5ce1af85e6aac92ae9cc814bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:355c0708f45e5c0c1273c209cc6d8c14bc9e428c8efc96c71ac5090973389a2a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:7bfeccd0ab6acfdce6db883a587e667f1d58d50625e4b966611d459a7a009e57
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f2aabcec2dc427aee6588ed57a9e9da2470b379cfc6d40d6b96aeda5d179a15c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:1e2fe99c65992c27c3415c8b636485460a60bf989f6446c350bb28d155e81b89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:08062fc3aa3db316bddb3467da07588af13e43bc5f0f1dd16e6a69f8de661d4b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:ab844aa64d8f0946f12cdc46fbbd58aeaec2b75a589eedc6fe9385d141c8fc32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:42739c96d4762d5c72b099a070db75f29af868f52515206b4b7180703b959ffa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:1c7486644b5b5483d0a43e1cbd49d8f21eb45f15b9ed3b862131544789e93e7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:12e2b064600ec750935d7802af8b472d13d23f1fdaf95988c685292ce63dbea4