Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:0cdbe9a1ce75dcd41284b7a6f0f3065fafcb4795881184bcaf653fc1d6c668b5

Manifest digest:

sha256:e65eb8590e377ab6bbb3716d0bcfd5cf0e3c8dce849b02a44464c98a75c62b63

Size

184.92 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:1320cefc99420fa45d07f619d1142d8dc0955a1c6474b19de8baf21d571d7d92
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:16d722cfda526eda0d2db1a65e6672b14c47f6b6bf152b639883ac5f1098b42b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:334ad0bf695978712bc536e67df3c061223c174d44d5c1c6abc57941e45c7ae2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:44fdae41961fd4fe7e55e01ae0b2b5fd460072d7479ee837d52b49e5e2c284fd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:ef63d592f753579f7b5d472457ef798629e3aa94b009b05dfea5427c5871e31e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:f80ba1d53e003e0edb40cf410ebdb59129eed8f6c53517e12be7783d749f683e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:e8e8a9cd6b517c70682991eb11ec17cc0612a0b107f9d6f5a5da8148c5e7f63e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:52024a81147b12da904bda52da09e159e836381d0de939afefbb9892de1bae78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:273bef786e9181c299dd1b17d5372b3a88269ebbebf8cd782dbc451fe1e335d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:cb7c6cddb92febc657eb7d259d8d63b9a2df9b04a24d5b42594ea947a393d81f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:d562cbfce7a96baf4824da8e8cfc4d377223924208c3c83badcb8229a76bdc0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:91fc82c17353118d124a2a6ac7f5b7d03234b33a83ff4632b6c809a39a00ba65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:6da711abe3d0cb5dbb758a115ea1edee581d330eb89dfeb9a12345a99e7a9b69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:5fb39651f716e0500c3972e8849b56c4289373745ebe4d220d946d802c1fd819
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:9134f90cda73e04ea60876d762f8fcb39e36ecbe778781ab432e0802d648c58d