Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:391f4d5f4135fcacb1fab4aee727b88212208cebdce4f384739f49e48de0491b

Manifest digest:

sha256:ea07d33ac198ef4d3e2c34e3183448d016bf0d4e1a56711cd5b454c8612f7273

Size

184.94 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:8005ab6d9c1d3564950af2f3f7fdd61ab4fc0cb01be29ce2bc8657e9c1e02994
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1a843c0382579d8ef56e3c67493d53624fbba347b06dfe29574ad29ec714606f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:d43eea3c3fc5e8752a986cf614adb7f60a76a31161961faddca7a6e9277952cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:ff0e5e30ca4a9c143055e8f21fec0a16c7747c5521ee091ed8856755d809fdca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:02b3a205a2696ce45639dcf34ff7f466dd42af2c8ec477dd633fc3036a92cc2f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:e31aa56c11f893fa6085a4e775320d404759f93f63d6c952e63c1bd1e88121f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:ba0273df3c95f17f9d76c2df36abbb40faefbfd8ccf1ace1a5248c46487589f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:167efad75c4e1c38fc7edc793f553a9450f4949e7a0a57dff7748e3209ebbc86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:a8410e6d03c63034cd863fc7c1711fa5282742618a0dbf7e955c405156fcb7cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:074e1572cf803e56226522a7a7aafbee640e54fd4049ece4f2ae477380cddbd7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:afad9ebbfeb6fb0fee8626c5666b78aaf3da7885d51c0da71d57a3a65a14b114
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:6d64aa4aa3011958564f1f15ad60f32efb3f63b700780ea7c44fbdcb55884ea0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3a13a906e6bd3fbff0261071a0cb6ec07fe845e405899da6419b21c4f3b8ed17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:aea023c20c791e0ec42181497bffdd6371bc4dc9b6317521fdf6cb0d2c49fde8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:127c12db3297a709e16d062943be3cc2ab609f35ab81d9b7cf29281dc2b5e711