Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:f2dd9e42a0b48d93581d77ea0b3c9e3decbcc51ab54c11129051546de4b2586e

Manifest digest:

sha256:168d0301d1501a1b88984b699051dc18cfad171d97bb7e7c4ff90a75f9b3d06d

Size

174.61 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:53cc7ca5a97230333f72bee2404688a3defd54a5ec35f7f824ed5b0ea462f761
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:fc5cec771e53afc605ade0b1b0e09220fe11f3c636f26e1c28a968b00294755d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:5134a0e48df5c5c7afc87becaf04b4506f1b8cf2a0aa671249f9c4768205f01a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:8277659f12d841792f097717d2a3a3733589823976a6be0b39e5308a4acdc1f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:08c804352a0259927afec0df81ae5af85dd67bdcd10a80b8d68000f22855f1ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:78eb92c48779fa2aded1cd65271891fd62e5368c190c1ecbdf6d4c2e26ce6ba3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:be66256ad8df8a1e7757eaa678860dcb2321e2565edbbf0af32209e376b7e0dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:1cb36cf78e8d8ece143b695a002cb0b708365fb554edf07a8266534972fd97f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:afff6183f3da7ebe41ead5f5cb188dacdc908ebe8c9f727fe4d3afa30a853236
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:acfce845c6905762ad4d2583c432d71de0eed1659de123b7c5c1ab52157eb459
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9182d9b0ef7dea2ef145298cbdd3d6735ef1d2a5a4d3e4cdd62ef93c3af27127
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:72b2e5b0652be90a23625a1d5e85cc840c7a200cda60792467563eb932156216
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:1f0d1420bd43a856109e67bb3a781c9b7495b1a064e9f1f6a2636231c87ee9d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:1bd63407632d2c981249448391ee75be98984852974996c9247a024369f87339
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:4ede044122641598351466b3373d3843146ddb6500e8d042d6120f22a7e4494f