Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:cb72681540410b6355030e0bf7cf1cc6e271e474d40ec09fd8518a51ae7a13d3

Manifest digest:

sha256:06b55199060cf0efc6cd6fa0c4e864a01bd4530921e2aef45a5bf291b4ba166d

Size

180.74 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:60b4e7276865989c2ad8243aabcef13ce161686a38fc76b83ab3b890be93add2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:fcb9265497d51d1dd44c10bd8c3ff4d5bb616edf8186718361ff46e4f08399ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:520bd8d942e57077025c79b3496b01feb2f0b7cb57c8c1e46e546272b42a458c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b8224b9c9e8b100bef195dfeef09d8cca89bb54bd77c562a26b3a4929ce0d2c0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:45f65e37692e4dff2c77eea89bbb6b939be713b7b0abab138e4cfffb23b9c9b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:5fce476d529bcb72b86406586b353b71e4bf1f36bacd32e895949e4e674961d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:967ad8b48e175aef3243143ad3b33db0c20f7a6cfea95691121184eff2fb971b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:9dc7129837af05936c5a9834ecdf95201cc2fa58eb750df33aba993a587a566e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:24117e381bc2ef5d1d96d9b0538e8ef752c88310e634c819cec85e0bbdf7198f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:3a67147172e08716401d3606fcf2c2fefd595dabd478efad990df6db5f74e4ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:b3a797b852f3f23b4075aea52732958b8fa8049ebecbe9ea9a707f840a433080
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:efc490a6e0fa2c14646c17a4fb48a16c25638d594c4f5b6996a03e19238606e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:522bbc2fa9a4e78a9352cae24bb815bb060fbcf35778e80298148a6eee8fae96
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:49a3cf38535e69396efb7a4753f7fc23db1f7b2f38f1d88ccc585884eff5d746
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:244188f87436f3c543948fed8da47ff0b7e5ce04c8d24f62d212953a448b4895