Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.11-debian-fips, 8.3.11-debian13-fips, 8.3.11-fips

Index digest:

sha256:36be955010eb925643bbd985044b817b89ee9755758268c734298b3928ed7b2f

Manifest digest:

sha256:4b96bc0e34d3606ccfde4cc721585f09d3b77359ed9b888ff44f4f31d7937081

Size

57.73 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:cf69770861e48aab22470efda242e8af8ca27588a93e6bd4a1f0d7e194e82c00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:3170b80b6cbbec09ea77c454db118fb2472f171780b3b9df962527edc2bf4f40
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:7cf355d406c9f3e96a851f9d60760d08da6bb1c896ea608dc1f977f94a5b888a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:7b74e244068f0551592ece83ce094eedf8a164250e6cbf15d8b2f77b04f22f6a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:ee726b18b2b78f545878781304959014d83730cc192f1ad3b26fcf7d50dbc561
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:fb3bb9d93c1ee693b32f798ea30914d4af2f359a3cf041a7344239749ce6e6cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:51c7e9d5b8a48d9d59923b47689e6c76f224b185b6d543d257be56658d1b7048
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:54afe63f760ba5b0016c6bbe03dc7dc34988e7768eebb1b167b915a24ffb89a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:6606245972723a330daffa64e173a82289b29cd17bae89f87d974ac4aa2c9ec0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:79427a62fe8a69c6c4cd93bcf5ec67354a34499caceaafe60ab15df13cca5289
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:bc3b27ab7c278dbd34aa05f4da713f253b503064c90be6bde75918aab39b0a3f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:b4dc38a1893c559f07a5e853eb330ec95fcce9c663b39df5cd0c74abea06e305
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:48a87b04d8e69ba34198abdf7e4e71d41f21219ef603464f70b04b91c601a739
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:4ec6046c5f8900ae5c5f06e9d93df33894421d10d7687075a8dc9747d99d08ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3394d2bd17821f345ed9d5efb8d3a23bcb3ca02888fb8bf7ef6ca1a424033916
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:b7d8a48926233a4885ddf48a0ebd117b17f8b745bd8fd3587809d0fba0de481f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:f54400b0149d63743c5e93c121444478bda01738d0025a78b1e98d82bfdabc9f