Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:81c8ddaab6fd0e67c13471b19195493eadb25b4a45646dac43c061408f20c674

Manifest digest:

sha256:9cf1d4803b0eeddc85e46f6c83e5dcc274c6bab66e7cdf7d95c4e09bee130b84

Size

103.95 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:4802d6f6637bddbe0e6f9db7c97fcf7049ea619f61c01a24f4688141a2059e49
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:5b2ffe57226d47f5e9e0daf25ea647ceb1a30b533a575e8a024bd86dada8c47b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:9acf62b9b1df507f065047055a42ac626a50ae99cbb4ff50fa45ae860a9cf317
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:c13ee3f6b72184fff3c2ada29dcd7e3edc00587ed4f06966fdd9b417c409f4a3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:6ad9657ad78f75bc9e86eed4ed8106339162b049df0a5b17d22233a3a3a5633b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:c16fa62bb7f40ec1531f7775b7d78c043e68d09a069de7dd4141ad74c5092e7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:8135eb17c752367166d198ca6910cfeeecec1092ab28f667e75ee91290e76102
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:853554791003b7cc049ead8bbeb4994289ca4f5106292f5dc13f16687f03abe3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:3f67c5a1aa4c427fdb94d96419d6ba9e07931749af638614c1dc3d432f279518
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:4d755a47a1ce9c6b35ab305a276c39e42f0153a1f4973513fda9167c3a86bdd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:77eb9790aeb828d85b0359766d730427d5182dcb7392addc2a89f67dd319849c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:9362f7775b7fdbd8f12248d3e03c5d8e71f4bdf0d428fdd75bad426e15e524d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:3072e75b0cf80ff12da062393db9f3b15af7b45f639a05c5798eb6e68db3e993
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:ab324b852c353c25b01bb97f0631f9883af060c25a104f4ab82e664e054d76cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:301f8c0c56c0edbe8079b399a6a18589b738f38519a6bafd746cbd1b6e0b77d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:b1212966135b1c055c91529329508199a6fd62183a10ee1687641823ce5ae3fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:f976e1921c0a0c55f5fd14e42070a0d2b426b5c9538cfd738b11d7825d6adcf0