Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:f7f9672ff76933f3758659439588f2e705151d3e9417b8124b7a378a32bc8ebc

Manifest digest:

sha256:098030f0b9d06809a6fdd49ebfe696890b86ab8837355b019f0373214d9bf8ef

Size

191.11 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:81546ed56cb60d1c66dbe645d985618469282403a528aecc83393c850ecd9596
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:9600005ee4e740e8b6136be954a573cd09a0c78c12f1a6b3fa5a55c551d88677
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:a2cb2e0f11b5bd4eaf398442431b5f86d59fb12866fbce54fe2e8aa16a576ac1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b506c8e136a0b486346b2144009b3a030cfdb461a61eadedc02126014c95dc3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:b0c734ad5e6f990b6b7bba648bd91a819524bd5e5d81f2396922c3e11b1bbf97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:1da5a3f444381005275a17caaa9b9c2be433d39dffe8b337937ad30f47c9ed6e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:31e2c84909942c2bac0fc2934531d005e4ec305a04724595791a209d590ce4e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:9f2f4a6812050d0effd354e0b9fe46a1056ee814892733835c4ebdf43c831a4b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:dd1192058adfa8320ed008f4c020f25dd89d02e9fa50a571eaf8627a925b5600
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:fc108a575ca7a65dddedf0eca16fc70370b8d6c11bc1a77ca06c8ddefdb36d69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:c72c37fd028a97e8511abb91e726f77033bec87ac09d2ee458d4890e93bcf9db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:06ae86969cb53c7c0b1c0e844ea8868ccb99dcd82620d878571099feb781d386
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:dd214626902680ed2f54e8b2b60186782ca4683bea540fcd01c0c8e47206ef76
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:4254bae0a2cb5150194add1981d334d74cd534e2cea2f3ea1426cf1b8b753c07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:d64b3fd1e54387b05ebcf8f60ae96d5d9710573339301e7e0c49bbc24243383c