Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x

CIS
linux/amd64
debian 13
Tags:

8.0, 8.0-debian, 8.0-debian13, 8.0.32, 8.0.32-debian, 8.0.32-debian13

Index digest:

sha256:ea2ce76965b9eccd83793d0ba9306eeef9ab2b2660cbf27fd2338b9a15b8ae4c

Manifest digest:

sha256:2b6a5e4e40e39d977da4ea4ab51e0f58718a414282d44f78fa175cad666f74fa

Size

63.12 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:e8674da3b3d0c4019f10c439c630f61037ff72740b2f9c4684e9603a1e4313e9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:e0dcdec6823a454622197edf6253505090326534c8cc25fb6bcf9e4e7891a322
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:dcd14cce80ef1a3534499ac47d4872eebbb5b560c8508a41d7f85aa65afc016c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:e31006398a7de796aed646d118b2050d62091639e6185ae9c2725f9f4f0bf02b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:41fa12638c42c1120364fdde1cc10cb7a5850f590f18c9a499334bc7c0038d25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:eed5fc3ac3e512a2a9202362c87f82f3b2cdc68e748543d4b401ecde72785b1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:214795847f0561826c9eaf525035b041848be9d7e1b33663bdcecc3a30c6a7eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:1d9cee28686990f1d0e295745cabfa3a1c0eca18ceabdb9e38f809b4efb344c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:20b1d32b9443c3e4eab8f887a26453f72ac8847aa3e475e041a08462c2602759
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:79c4699870a2ba6d6ba60d4a396de3b41b94d8a32fb96103fe4c250d1022244b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:0fb9364e6e1ce3fb88286956ae3fac6fef8796e316b3df2119c815c276063f42
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:97d55dc186d8039de0c15067bb3a24642de5f1b09d2341fcb0a9cbbfc01b9d5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:4a11c56852db6430c145011dae42f8f5d694d72bf87658486766ac584bd36609
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:cfceb52ba2e14382228f4c271ef103184652b5f4c60fbfb01272df46fdcd5776
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:7533f07d61be014c1e5da390e8b4c6b2221a10b3ea3647b8d45534b7ea4fab96