Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:d3a98aa991faf6b4214ac0d612a162b0c92a21c7a35eabf038004c992206617b

Manifest digest:

sha256:0b6b327ea689d23b819611d8bf326ac791ca4bd94cb54f5a89f627cb4d1b6b80

Size

174.61 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:f7bc05d512024e66acb8e3f0e9d14900479c36f99ff038407361489106c74967
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:54c996f86499e3f5b2876c0782882b2551ef3e1b5177fb2bf625e57d5e108bef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:42ea498a76636ff06f5ab32792ad4410a070c863f0ca4a82c798c045d5b57e20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4923e71df1882861a957c0f75ab03751cb1ac403580410c04127c69b98f1c6ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:60f06ff2293825b8afded89dd35714f1e97da5c64d86f7d123bc94807ecacdae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:2510be6284370ebbd61d5eb1ba85e5fbd9e5c8adfca1deddbe0cc00841cdce99
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:dc60698c0370e95db2490a6237c9a20050227a03aec20a6a211b06251167a427
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:1dc0ed9aa700462cee8b7d5c94fb78d8cc28da2d2a50a32ae9dd80aad8dd0258
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:ab5e09f755b65a7008c1a32ade06a27762ccddc4582b2f51406de3f13f96c9b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:b561ffce2b15178bd8a3c579f3be8a9632f782c6dbdf478afee83a884ad7e234
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:59b59b39e72eda0d040a680d0af58077d1ee0e9fd1eabf8a4e6f8841e22bd347
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:12d739ddee4cada047f1efb3d5b55b2a2d14b81451919b91e80299ca1d3c1c64
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:65c05fe3ad690748dec2f605230d8170e8d53735efa5a8222dd1f466eeb9644c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:29a78b2acf999e0e4b22a0fe2dcd68a382b87d849c77478e743404983d212cd8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:92bdaa086e2beae0d33717f2122abdabe4a1ca066f056de0aeb3ed0d7eae6b46