Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.32-debian-fips, 8.0.32-debian13-fips, 8.0.32-fips

Index digest:

sha256:dda658911b9e47bc879d79eb0cfe59e1c2ce9e8adb67bd456fc91dcd97c5dd63

Manifest digest:

sha256:2d3801aeb5c79b548b945dcc070c72e52b4ad3f07df16907ff835e64fdbb2a60

Size

63.87 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:5c185f8bb65a9af3719ea39d4983d1b0148e6fe69721b3a45afad13fa13c6711
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:1da501e5e57a29177ff505a2e24f6792be5dd5c92964d55ff784f013cccdcfb9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:8427e54748a4342b061c0f32a36f0475a881c23d6a702c77a40e70469a0b58cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:51adf2fcd0387d50d6f93c6c83a1bc3dfb72909e45f1f675b2a19331c59efed2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:3c82580262b7c6b2cd1a99ac1bc8c23fd5482e3c949cc1f0ecc378a18551af93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:ea534d0fc433edc6c18756c3904f36129c3899fc5bb898f38ae0cd22497fc2de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:16db82b2efd61e6d000f0ae48d5410171d853331f5721eaf4c0baca69d678c58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:27e7399bee83cc08acde26b3fc496327d2ac9a13d6816e25c61c8014ecc57cd2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:28b60a3921dfde622af68a62a87100a2c8fbe3103fb0538b06b95249bcd859de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:69d2e0898487d4450d7b228f21ced634a1865636e72316bf445d1ddd982bcb44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:40ba0f515345bc0ab837303f664d79529bff6522cc868985b257fcf080b62567
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:002a95264a3b0f0fb1e1b596ff6c84f89117a10271175666cf91b7cf895d9c23
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:6627f61e49a1d23ab45257ef720ae8f197e1b1af02c78e8085eff94e4e6ffad9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:8960186ec914bd2489a3b3d6c32b60b7390f28f65ad82883052c991c7bcafcc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:b9fd175286cd62da08cc404a769b734131739cf760b7f2819545c100c109bd43
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:f7c19d57ab52ee04e776851e05ee3ec3e9e569def6848bcdb5ff7085f3388a77
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:625884d7d48e6999228eabcfebc44bbbf2139c2d1e6367d7c94724f5c9f4ca53