Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.11-debian-fips-dev, 8.3.11-debian13-fips-dev, 8.3.11-fips-dev

Index digest:

sha256:c7a12ce0633e3376ccc8bd546db710d446d2b93ec065627624e7f98a94b202d9

Manifest digest:

sha256:e8574983586e2f5cd71352ba686e90a601ef31862da8a22d9ed02f5b2d525d46

Size

185.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:8061feaf58941baeac13a81b1ce1f7a9b9219a9333ec082c105c5471b6922634
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:f34a9090ad4c7c07719ac3924fbf9cd459fb6344f2f02cd186b5622cee29d113
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:ec6986c08300e1e3d94505a02e27c0c6c249e7c22816a54ff8d9809bbc2cea13
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:b05e5c2e08896403fd6d2a797767d6848875c8f7fad3a436156ddd3fa53de463
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:3021729cef33878d881ce731b911f02246ed597016151b9f51f5922892b87d6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:68606badf981ea43fb839069981035bcbd1ffda04d91721d0a905b81d3fcf040
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:9566585907390161192e8d42b7482145e98bdf02ffc96a9b1898338bfd35aee6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:1cec286fa93a35acf76d3ca66b25fd2f9c92282c08b8aaefbfcccae68d04a149
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:049c30a3101faf0f95e7bbbb131aee14260ec9eb8301d723148bee25dc1afa3f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:e631e937959e4eb16d2800846a67cb0df1943f8cde95b2126f3c09d8eadbb3fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:34d8b86c8c73cf82a68dc3d1f650e27eb3fed80d4540cfef51b0aaaf578a88a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:ca94035a72a0b4a8d43007e00c45a55c3171d71f500414cdd2a49a2914a8c43c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:e0248495e94a9495896308a308639947890c9c10fc6becdf4f78e05870727d8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:68b5a38c2c5931f5fdb85ca8758c9d7a15e1c9ba9834128845617cd68e337975
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:39075294074d8df4ae1517a17f4f7810f7c828e1d1e9577634d23f17ce2e400a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:3260d4f1b794238e5c26c96333cb40203226cc28990691ce006732e7df51b4c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a3e635acd1fa88766a45f8fb12942182c0fed349823bcb54498174c3be5c0c70