Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.11-debian-fips, 8.3.11-debian13-fips, 8.3.11-fips

Index digest:

sha256:c7f0cda6b62155b9f00eb75fb1b47eab74063b2241a29de80e17af1f0a159f91

Manifest digest:

sha256:d5b32e081ca4381aeca802d38ec4c13bf95db4a581ca4dcc5557869060829668

Size

57.73 MB

Last pushed

5 hours ago

Vulnerabilities

2
4
0
0
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:6f077dd06e67ab79b941d7f3ab24d78b79e59bb53bf0d1730847a7de37a799e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:888a8e7d387e7ffda33fde7d23d28e8a1bcea6c097123c49d761ffe82fb76909
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:11b6a89237eb9b96b7cff891750156523fc7ba4a6fee744ecb31c7f5accc9772
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:95480eefd93412aa58a09474f67dbb222f930b182c3d330b163a3182928693c5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:42223e233d9d28c78ce92c3b8c9b38ba50855405c50fd69f833c7da022affb93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4a858bcf8dfbd6a29eb02b6fd370c6755ff8abdc2876299d20dd9849f093c8b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:385a62e7d1a3836902353f10ee47c353d12705dd7376ee039bfbcd56cdbe7260
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:01b8af20a223e45b3bcb5779ad9d419f3b12237d55404b09b3367a32a648cdb7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:2980b20c295fc7eb0682f59736b86da2bbc8fb0dca43768798530ccda9695eb7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:6d08b6549e997b3cd2ec72d7af96baeec156cd1fc8aa1d639b5616533d3f1161
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:203fb31326fc7bb7c9b4a6f0cad85d523ca61361169910f50358af65f03adc74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:622a2ab16e0d55c33da7f23d8a27cfbc4005c8fe341d1e1950fc91a542874f13
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:072cb4c565e62c847e18a159676f6dc3dd23b958e42fdda93b711a25ac68551e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:03af93c02eb62f7f39d81ab8cb6c1a962ab60b9ac25f5b3e60f79f91e0499e2b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:6d0eb5e6ac6fe223f460ba08b5cedd976a1fe7d12cc6ac01ab06ba33cd08f07f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:b5da9f30c54c8e64d637f27fcaf6551ffdcf697e5fcd5c1a82e6ad79d71cd91e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:becf45d05cccc2a7d026a0ca3750b7ac46c00a91a03c7fe9ae6d97456b8bd183