Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:b47d4f50b81a071164fc8dc5b38ac733d2462eaee98b0b02d37018ea8bf8e947

Manifest digest:

sha256:f068378e812ebe14643c896f52d7f7a7f7c5535a67168ce414e2bf95fc6f06ac

Size

184.94 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:7aa4d2f217e483aa279dd71d3d475ba85bf16050e47b02becb352ac16641e7dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:f35c3df8ce79d3f46354cffe76ffbbad6bbdfc60d3f9dab79f50cea3e5687f16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:339e5b8cf3c6382553bedbbb75e9434efe08ed20d022ab166d019d3c3d6459df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:846cc899860fd70eb905b531f322fe6ec807fcb18eb33c5d7ab4af0cc68a27fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:13c2c448bc19e2e74fc7d98b64e6d57d2788cd1538b9fd80291693cd8e39e998
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:873de7ebb6e9f470cf5a84245cbbaab85f9e31000a0aa3a17c565837cb7da27b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:17ee26ec5d92f71d18d5eb2ce0f3e2f078d7438b6d5f8a93750e7d190e3ffd74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:ec7709f272a34daf650dd0979d08d3a4c56d56fee71e2bf5fe78dcb78deca8d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:bab60333e3bfe1f2657674b0d399a667dcddbb682fe63409a84bc19ba2dbf696
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:d74382e88ec1c7d344814fa95f826ac6f8f3c35fa253d719b0722ecb9c82be71
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:b1afe618ac46689e7531620f4092a3b9ad16161d0eac1146b60d6be16a686dab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:678d135c48009a05ad85a1167d6ece78dd46100c6d8c5b32976256851658f215
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:9e01afdb81aba8e0c23f443a268b95602fca9f9090d8c440f7b3b1eca08be90f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:e3a2b44808a2b55e9166e195cc3f47e56137f02823417b57b6e021f74be9f65e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:98193f9c4dde229712076bf825df49ef28d8d01d21b4ad8501238f34871c8e99