Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.3-debian-fips, 3.4.3-debian13-fips, 3.4.3-fips

Index digest:

sha256:6df1dbe32396b79c289fa2479faa954ee7f831b6df27ad8214656b433c819a6b

Manifest digest:

sha256:a5c9d9e995470918f1985be221e0deec9a6ef21c4f29deb0843a55cfc847e38f

Size

92.20 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:ec3eec2d7b8b9ba2dcd67965e91646d8078c2f17f396d4ee1a1abe10a7043d6b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:6bb3f2b88ddee8894b996699d690330eb1a6ef680671e9f8acc03c50d9854f3b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:8bb8ccd7c0730813f516ea48ee193f323e012197dc82594185a58ab99a8bfdeb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:d7d714e1192bd92983631b5c07f694153a60d8bcbbee872da4ef7b457d8913ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:1022fc4dd327ad5d71d1f85aace3737981f61f64227d427c17b23e48695e7616
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:96ffbb56ebc0f02dd367100a33d7853824646465b64e67aab450dc3c6b82630d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:edb7a8c31280bb74a01874670cb6f355244595ac90a22082ac5d447d137f749d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:75adf849c035a9af48f326448815a1f78a8849186bf35442b79011e70ae3dfe2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:60079651c2329574487aaafc2e069cedb586ad86e62af1614d1a2fbb9b85522e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:0380ffb0b91afb88c6ecfc6bc72d201d3f5346f008423f052335e3f2959dc9c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:898d7cc5ff4b327763d0a2f7fd884594423fc7b674be9f18477241d5d405a5cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:b43b464fd59de7f446fcdbe8223f73fdf4dc616ac99d6a7d6f562595b84f86b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:876599a0afd145bfc94721fbbbd65fb375d361ab00c43196785bfc5d1f67fef3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:8bd70b2d2408f69eda8545eb2ca426be380bcd9db6c5ddc920e0e50c34c1dbff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:20d26873daa6320382b3ed6dc5d0269f32a5cde0dbeb639964cf1e70ec9d2bf4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:c5dfc38fadf8ef93445eeeedd3f83b519d16246065cdc67e60690b86d549b196
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:05c7e1edb64903890edb7d2bbe7e5cf5cfc37f901d3be3ed88f4d36853ad657f