Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:9bee271221bb88f58432e177794a886100a62a62e20f06250ce3b51233118d0e

Manifest digest:

sha256:50e85510a4b85918fcb2b66fd39a02a4b8f69de4408e77fec1e8e6ee5f68eb35

Size

63.13 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:581e46eb5d48d5a7a07ce2d5e275ce9a52064e34accbcbcca604de3fb0a1856b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:252fa6079522131290d6e7b48f8a81ff6dcd56c59dda14eb8911b4515cf02f1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:b3796e9418eb1325a677f3bacb89cc4f767234a936ad50aca6de7bdeef25a1b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:f540d49dc4f982a2af994d601ce71f674756a20740ff14953c06952aa7380719
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:2765682c0bc05ca05e032a8361620caec761ca897ddab4cd77f6f09bd3a21fe2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:1c6566b18336c2b95651de259147cf7ad7705c309483e4536f7fa38af6d22b2f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:f5feaed675052f191845c0e7d9779c87e48e36f08b460f225aa41d46b7af3e35
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:84b849e81a5767dc71cb6db3688f0cc4f4a6545591d1d6f7b15b34cd277e66ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:75b3e61b75e9f97a7d7a0a5fad46a88ca81647b1ff36f700cb4db9d88c0a08d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:466c06c86a67867b9a2b36ee193c39474172f5993d4f056e85b43e162da8cac5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5a81f8db0a290b73017066a2b0ffbb323abc6a881b0bbe7c08e7398fc2f81256
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:3b15df651c17f326b3db160b20d5d1942e58fe5b8bb2c8914318a1613340d56e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:29bcb8f11c42b17b24fe5e304881b754be0bd8167bfceb380c7765ad1a40e153
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:877aebdba0aa795d8ee5301cb48e605b28f4f516d408c57181362c572fe28d56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:1f22699f32567645f7e68434e2ddc6bb0c10ff5d7eaecc2fa4c8cfb7bfe83391