Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:7b2f16ae100df96334b8ddd9262f5b304cae60ad788109d9d192baea09e2e2b6

Manifest digest:

sha256:38ea1e287e32fc2f571e8392e5af0e1c00a1ca5f00e94269f832fd8d725dd27e

Size

185.72 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:80c0d3d62858ba01bd32b1dc1809c3ccf5c612b36ee0462287cdda5ef5411948
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:e1b1d6f117e8e3090cb7c84253adb51dfb95e7bddf0d1a5b0158c1f769b32a0b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:65832bfa8f0e16eb8ca18f3056ea728a64af6d950f7421c5eb4018e055c2ae87
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:50eb52d7782e6fcc0bbf1ec16bd821159bac13c4785624ad13c45a7886a44289
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:e4da11ac11cbb0f74efec5524eee47775e5a5bc85b375af6c8a09ac1a2bd45ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:959168d178406b019b234558202f9483721c9f01e1bf54ddd1590326459704fd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:958a0e5a3484b2aad29062a6123046d05961f4b27bda99572bc621dfdc163f00
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:846af5b07b31825b0b6c7437690d56879b022d4e9c585dacc2878c88f948b976
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:942e281764683b4db976799d250f5733a5a9ac192e356166ababd1cd1ae39487
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:35c075519bbd34ed4ed8d9feafadb664efd10615cab88b9e383565d90a18bf34
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:20ea19ba92bd868076cd75cae574ca2e6a89e28d3818e5d71a1c5664754cd61f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:ca555995c4155be336ff0d6d416a7da99fcfa4767e7aab5da2571eb2783a2d26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9dff9f080b4bf191902e479a2b09d9451a48e45b82eb599c32b01aedf8c362fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:08b4c08d6a8f254376e6134ece39142c76ff96c394fcb52772957df6a07b86f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:ca70dc70306a7e9f470f62e57ff1a6ea8234ca7858b381f680e01fe45d072d14
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:63745ffa6772485af736ce44d5f0b27a3290529122c9578d0793bce92a4ab54e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:e38410124df99db20f1cdbad2c21b2d320ca5de8af1f5fef53a48222fcfb3c49