Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.3, 8.3-debian, 8.3-debian13, 8.3.11, 8.3.11-debian, 8.3.11-debian13

Index digest:

sha256:2e1219223a3d98f0b071c3b19fe85f847de76803038a93678769e274288af554

Manifest digest:

sha256:fa8264ac6d059da86b8368a9dd242158bfc6069001cba5806264f1cdf1932936

Size

56.92 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:e4545c8f9be733787fd4aab1237a5cc7440a7464493c341419b12661119b1450
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:d01e2cbc0f882cab090acead53ff9f7d4665fa4dbfedbe84ebd9d81c19cd7e4e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:10695415c3d703de22b5175dc32fb5599fa3378639ad33003e8efdc55a0f8d14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b91c551c02d83d9c95381ed6913067fd02c069d833df5d35bbf5c5064114e290
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:3f7cc5c32ddb8fe40c35debe22c0564995bf3787295ed58a9ae0b5eae000be3c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:4298405cb64d1f8710eaf2d9142bb6937ad70210d865c4a52161d5e436825a17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:ef2d5a0de396c146fcabbb1336155a86a377d09575ec0e66149e3390f9479f24
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:f965fba81657f44091c4f555526e2565bc4382ff4abf423fd949dcbfc35640eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:69ffdc93e317152cb458d3689bd68f57d24a8122f16374a5b1499c57a390d69f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:78787127eb3a72f8ba0e0e7b4d29a0da641a8ff15f28263393b3a36d297d3c1a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:c22b0c0e689186710e1f9465f22fd944f9001363cb65fa77f3b81cf2d648ce97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:24f5b5b5f4814d9a662bb8304b03eaeb33c25273061707c5377b72e959de0153
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:ee5082fdc6a5c59928dd00a08a1f457201071a3a884d2d711c34d1ac01360932
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:4b0ad1264f054dcf0fb3fc81d3d5edf823120f4e4c097430c89100932aeeff4e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:e035cd594ac0f84aa5dacc5061ba489a7287f34c85f5fdb1a4554896c6950a23