Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:3a82980aeb80ab71fc431d01bf921443b54701be5b47150bf022ffbb979e91e1

Manifest digest:

sha256:2de9cc72babb0ca0733f53d38941ced9945276ec6ccefe5afb39e91c180e5c2a

Size

184.67 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:b2dcf4b83e1eca36ff92fd489c573ad44c3797a24a94705010136a2279cefb8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:cbd7c11ea037ad1619abbfd008abee1b8d970ebac38048b72755cd647f765ad0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:e21382c5ce64ffb1c963dc1bf868ac7a3df16f80d783f365c87276876375e778
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:991d8d70ea27d99c02c1eb91e6967dfb7478e07b14860fd0d244646692689c59
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:b2d611255d342834c4b7bac3ccabddf8ca3bb93d29e5ea521fe8801f38a92cea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:baee239c0f01ea169546195b35a5e996973ff54f167e00c66cdb4ee3d8509334
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:5b4c926e2eedc473b1e156abf649fbfc13cd870510b20419815db8f54038c0a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:4e445278b55c522e4152ad71ab739b0070f61eac91d13ceb5791da2b3da603e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:b668deb950a9d646bf7baae64119a8c85a98a2faeceed70ef07120320ea265bd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:c6f6c7937bed55eacab8b3c11b94f6e7d0f3d7aed540a439b941811f9e0fdc72
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5b056eddae2fb9a449dd4408062b091d5425f561f3494666b693c4c4ff99f101
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:621ab862fbacd83ed7fa2639d8667d54123187e8005b0066795b0656b659cfeb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:7f36dec36a61ce8cef21c1f9f3fbced2d7782edc4e826f19a78d41f8f1d68f14
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:1d566b2812086e166fff3dc0713d5311b62e2b989f5d1b6ff37ec76561ba9bdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:9ebadd4cb7a6bff56e77a3f3d731e8081d4b39a0f5f647fbf06847c21b2bda1b