Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:75d390a89b2093307b9488714a49e4d7e0872e597e1d91104ea625b46eca5da0

Manifest digest:

sha256:e59eaf2816846be92a5de0980a54fc39f472dc674e99b830142cd207e347dd01

Size

185.73 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:1dd9c0a44712f418b3b74e5c9a6c5d3a90253a56c12d04486603f6dc14c1aefe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:a044ec02592ba46c323fb20a78e517ab1f7507db41844ef42de50c6e01bb407d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:6437a8b70e49e81df9fa90a0cedecc84e56b79499dc751c2b37d99db75ec3456
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:04dcbea2fe07babd063510d9dcffff7129ca3a3f813aeae7cf0d1aba98ff239b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:da8f2b8b175fb1cdb1d235d7ce0f3ab91455cb64b0b32c3ed303b25d38f7bdb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:7accde917a2c1a9c1af400ad572a7c7c556fbb438ca6e757dc753390371bca37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:0d2f6d1636a45418fec2c8f7e458e59136a7aefd3236ca6d7a86f973fd5d3133
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:7c9532edbde08c6d1ca2333120cab59866fdb94a106b03ac17427ea888c1b9eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:57b782d327dbe0338671f2b397e90535babce7886e629249197d4efef29d7a1c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:2d071f78655a045a4086ee2fac4ff8f5dd0db89c39efdde04d1463d03ec05a64
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:83711a915a11d01b9d64cd6f146f6e2e9df4b7ee4fff45427da23ab1c8264db6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:a82dd41c044afd4207a725724a8534ff9ff0284701ff4ce9a2b27f90aea8dc20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:13834ee5791f6c119b6a1f03529dbae28c23710de8c85a232d975409bbf7271a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:765d2d95090655315964c8319a4d88b2f08c2e837bf8dc9e74ea885cda2179ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:5e8282f817064b375083a7fbb839af7d00961ecf4dc31cb71effa6c320584c1a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:f054ee95916dda0fafc527233e434daf87c28d659952b8587e52018b90aad001
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:953c297eb6a32a585c7c70aebe75a3699032d406e372d78c24ad9810f75edf53