Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:d6f8085acf3bfa5d1ade708378e19b7acdf7f5102b73d7c334053d2616941c1b

Manifest digest:

sha256:e9e1c87d3a45c99a52c9a24ee4910e2d890f7566633bcfded28f3ce61cd9353d

Size

184.94 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:4f80902cac75d54a84f1f6ce57d8bfc9b2df1e0eeb264984e4b4bdf3e2780299
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:cd4faea40f72244db291e66f55bcce57750599e8a3a18d383bef36326f81a4e4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:1e499c53fcacd28397fe3a384419305498e6ae34d9f6e337919a5643bdbd9394
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:14dc1355f497e74b2ea9abffa33936e30f921a6f058d20fe985a32766ab74ddb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:25fea296d170e371b9be0f3cb5c47de6a59b1c3ec0090865478ee997e7ba6250
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:5406ada1c0ca06149d4bcc3054e557c8add401522ceb2d694cee191b43142f7a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:f8f65a3db47df37960d35e2f1e7b2cfa22c9629b58e98a35469b19dc8913134a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:881d149ef10776499603fa8379a34dce50886e1b481d8d8a77d5755cc7e9216c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:28a742a3b5b2fb77eef37ce1549ff514f11cc5137be78e98d7905bb4ae88ffe9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:4cd7254895eb388ddfe0972eaddb543309b01f3dbeba379af0e05559abd74efd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:26b1649e12dee6a52252bd699a7a240182b956a6b1960449cc9c1f4eb8dcffdd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:2e5b35e830ae35181042f4ff0f01832889aa1725070d8e7cebf7d2adeb0aaad0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3d8ed445d38d2134ebe24517f4e697bc46327d913ae694827c0732a383e719a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:6176931ea000f143a12ffe8669e3cedec3f9d9e40f90c43eeecfdd2890b045cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:acbd96c4abfa9ae0a649d81f522d2aa1b46afb4e06e237038aeaae4c5eedacb0