Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:4f550a4bbce8b805047c6ded0e3aa2ad9d06363c3170ce4495b85736779be4a3

Manifest digest:

sha256:bc355bcf15c77b87b6418b6462b0f75ef973d8523df53edf8eb3ce94e622ebbd

Size

174.60 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:11f2d037570de816833712124a876ebef0f3660e588cbaaf57f2570ca91271b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:dfff2e32636137f877f58024c5a790d1bf81b80f6afd00013f39c851640bd145
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:5a366241181e94bbf02d9fc7e5e1d515be4225b9bb8a3ea07b2d1555f975e1ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:45f328eb6028cba477015c836e2b002f40074e2abeda18deccda0082fcd0df8c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:a2c400ebbd45ec6619961c177c75ca6b9a704b0335237f11d47bd0ea3f52d1e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:973e61efcf439f9192ec2744ae842c485baea8c35de0f94b98dacd7bff479512
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:eebd9a90060d8e1ef1c52a6787320d39214d696b95b3060bf33002b38154cba6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:8e905723c59b5476f74e4a8c2d42e2b4a863224ff5bf60db0630bb7a0d170cbb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:476f006a2660895c8ec77ea78eefc679d962a8bf247329866de5c002710b4fe8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:2bd05ddb5d4d57e3f1f97b878b5fb2425130f536b4435105cac4a22f8a68a534
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:7fab7b8402258bb8fa45d8fcb55268eba9b9a647ecc1ee6d87631a1002e6fdf5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:2b02b45d486d9de63975b559ea04f80debd9450444e52d4d04eef5c79ea05ba5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:81dbabf6fe43425eb55085158b76daa9dcc52d27493c1ecd58f66d7907efde3a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:f656fd8caece24176e4045abbc012049912e6127ea517c01097c65fb0c131826
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:e459d6b4fd1f526b11596d5e8bcd64f872de18d225b76d8bc5c298e10aefd56b