Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:5987d67010ae031fb5ccc127c00150989f439471f1946ef19a7c75f50ed7b829

Manifest digest:

sha256:a6c9176e82a0d236fb60da679a5b0bce8da6b713edd9eb14bb63eaf7343cae0c

Size

185.43 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:8939f9ed739ccdd53bc3b32e2e14dd70739766ba333de995d51c0779d547ce7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:a381d2c28d915f3777d09050bb3f4bcc46621a65b42a67a37d518a757d15039f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:6edd908f1ee5e42d4d9135aebefbfdaa7d6c0177097114da98f0a1bac2f3d73b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:8c14bd08e47613cbbbfb7431c135454fe1253c6e57f42bf40c248accbddd3804
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:b3129409ae01dada3d4249beecabd607bf3587ae73aada23a50e265a0df3c31e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b2203338a2c0eb5342998689e326973939203a76b5ccbcdac5751d0927cad292
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:7b4bc19d3b33a4b03be3adac8c9b4f88d223c7c4bc9f8f4e5431b00fe1af4588
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:3e8eb3f836939f139985a9bb4accc04e178cc0279537e2489be52b0b0117ec4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:6a0fcbc064112bce9727b260574e887d6a701c5bdac539ed6da077ce9606fc82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:8bb7f4302d942d6e68b145ca540b92806ce69725b5f0dea9becaf37de8aa5b3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:5a55b89642f68b6427e62489412c246fbe7206c859a80b75683824f86d9cd831
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:bb2982086942aa70bc7a15d80130a9641630548b8ae06448a3ab1d3b6944db4d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:f535e3c960770075b152b648963e10ce31955b7d41800d6ba2bb47128e6e55f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:1750ce532e9d625df9412b47380ae4a19ad3c96e99ca45701942cead295cf234
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:ea9938f7aa1cc98d798cd575144fcb32db7a624ab6c89a97a7a435e3bfbeb520
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:e8e41f6c718500138b88d84a55f4abd07e50307d94c3aa832f17e275e9dd0ef1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:41d1ef0f53acdaeed265c9e82d69f62105a443aac7f06a83618ef2cbc7167ee6