Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev

Index digest:

sha256:59860f41cbe49fe5c75ec8f0275ef9c50166977ade0f944464b8a2a5ef9a1f2f

Manifest digest:

sha256:fc763949bbbeac8c436f987f9c65cc94e1af937a99bf70b66600a865d9b2d783

Size

103.95 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:06a592a96d3f240583f92f8162cbf2fe436c7c4cb349c7a341b8ac9e396d1cc2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:c8ba222baf8f111d37184ceab9a70f161a21b5ff126a33caeac3d4e1e78ce34a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/couchdb@sha256:636598ded304c72a185a921bcb6910365e7206333b25bb03f4eb4a04a0394b33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:920ec9031c4f7cf16fd5e7b8c2352b902abb47d52610f990d2769e7c418fe106
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/couchdb@sha256:e4f8801dc01b63c26e1fed28c3516a668465638f63cf94a21e79d3bf9c12b9cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:4fea4bce72219cef5bcfea6e9fb2df170ac7ffec87f906c8810abf25cd69d2e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:8a68c85256a2915a479f73a2ff726c096c8a9fb9a9f56be98e3ad5c0f358a685
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:0e02ca4895ebdfb9dc0f11898e3a141f5eb57c75eed86b37bef49febe9e69ede
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:bec661aceafefd269e134fef579f594197024a3845ed3c7d4f852c80f19c248b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:f49856fe23bea14b00218ea68022873abb0f7d456e26db693cdd4fd5dc8fbf74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:d351d6d3110606cc622884fcde968754d03d4c5efc3d196c9d1c09d430c98f2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:fac155964f1fdc82b02bc31be4cd3d8a31bbe1e615e9e80c33cb8644f187dad1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:c20fcb9094eead9710ebe2962b53cf215ab92e126eaea3e1e809af00f47321bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:404bba89a981a77b0cdf7719c593eb9139a8c81412e90ade44af8c8277d084e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:d32451d3ba12b3ff0b8b8d12e840236b31fca17e75f70ec053252a2a483f0287
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:b0aa208df29368d7c5961546d4304ca71e028b1fddf2dc9d20ead120ce19ed69
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:bc5b5f86e2b4cb1a49d826755faa79ccf5ba77a339a8ec1a53818718ea83c6d5