Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:2880d38fa89d895fe80259fbc40d8e1c076d603455f6d83a865ed5ff7bc41834

Manifest digest:

sha256:4fec6da99204fc00c13837fc5cf92ff80a96d799888070aa9ed7908766557b6d

Size

185.73 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:41c457e09c9b9cfa00816517f9ba79603ed45282d7edc906a24c83eee7464194
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:f80ae51b8ed58da6f97096a2c48ac223861314794f88b6c7c9b3997e541a20a3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:6fcc2f9eed13266afb0cbdec81f8bd697ec5c9aa6020088dff9133042a848618
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:ddd1ee21111f05e0a2401f2da4f219516b19276addc02abf8eed13b2e051cd8e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:c5c2413efaf8d3d02b6e8465924d921ac323a019a74d121e2a218300a694b892
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:6a418dc684b820f0d3528365534c33d3a157beeed55e5d762b953a05ccd086d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:5699b805aec4775dd3eb8fc7753b2a52c5bc764364a1bff44d315aedbab89c81
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:a7e4ce8f4aab6e564b352f8f4717d4fb824cdcc159c59628d424b68f4f71c630
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:6efcb0decf5f76fa2889ccb491e69d16ddb7942e3d38749da0bdea8883ee1777
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:3df584656e6f47e558bab8d26b90656b927a3c85fe296fab3ddf063d39be8208
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:6cffbc098a5afcf8b438186af6ccf935e8f256ec61318db1b9f5d11abe412407
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:8fb4fba7a73279dbdfa6339fb6f95bae1179e88033c92ddaa360a6d892abf6b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:297557a2ebacd1be45c85243a25a29e30fef65553d525bec3bd0a66dc695c416
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:8eb077f26065bf2b6cd265126fe1ce2ee053e5e0f6a60b7b993b725041548d51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:0f4a919d4fa2ea30627b74b8bee9e72436b0d049628997656e12c2b4afb0de3c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:18b4196eed36718e4cf806ca5dc6e7ae465518e3dd69ce70d68e88f6bc05ad25
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:951dc801501daff574385aa950e9b6546f6dad8e3870df8b0a5b2aede8eb6bf5