Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:3e8b0eb883386228f1202fff947966b040ec7290a6c0747ecedeb20281e8dc98

Manifest digest:

sha256:4e6dee99b6921c1f66afbde77b9e1d6ab11f286b5c3b14c53306e80f1b544d4e

Size

63.12 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:46fda66305ba2f922f5baf3d104d0f72ee281fdbd71e9be729f8c6317166fdf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1bd0fb5787dd82bfff866e672d504697b0d2ba1f768933b3bf729ce308278e16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:a4b6d7c25d38c63ff963d2835f6e2ffca91b4584a616894c479be770c8c05d8d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:d79dcac7aced2527d159ec9e0639425862249160bd47ac852e455e4df76374f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7194eed48a2842ab10a6c745a1a9a0936647d9287a1254e2f09383e3baaa86f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:73a73ec46fa1ad9ca6edd06ace56eae088296f750ed6f6b0bd9519add27dc235
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:7600db568c1e62e423be117113c0329d59c9bc460169907ed0954bbd5972b1da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:781d6d6bab769641aeeb8ac8da1222db689e84b206d78031d7d7742fddac01ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:2564b37cde1da4d3f640c176d711ef5d6aa261318a23939ff1764216c6b7daa1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:7019446e08bcb992e21eb0ad74807d3e8eeb5f962cb785101cd1abbdaa803d95
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:87fd2d3f68b2f7517a36b2ca5aae52bae476496f068ba86763a9dd302db78b38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:b6fac5613a84121732a9a4973acc6df2594a9eb0d50ff0db28690cb576281df2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:d27eb2e03545580f155770ef3c70e99cd02019dc2283ffb316d7184ccf3a41fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:b383de0367a49c4f4ed146e7649bb6548793a182bb1764a8af9fd5c6a5abf021
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:9328b288305c04f5d4755ece63bb0b41fad1b99308bf0e9452586959f3f247d0