Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:70e8b2a43cc7c2cb8c6e95ee1f4c77cf034b60b0f69ae9258e09345099fc3f16

Manifest digest:

sha256:9a091a8f26372ef0c5373ae98c25ccfab50182090616173d4cab73e5a195f503

Size

191.11 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:6f70b2fbae565950df9cc4f78afcfdcd01b896a77e239d557724a825c7128aca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:99c045a6eb8724a899fcff7e8fa17bcd7457e51fde29b210e7bcd56c783f2b25
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:35913a111d2d21c73f820257baba1f373d3fd8b54b8bb3063b270e4865e53b00
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:31faa8218ba0fbe5834408f0a22da28ac1d7cc38f8e91a73645ad8d23b300153
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:9266745bee6e361b04418cd810ad4116fc2ccd11b1504eb98f2f52fe9381bcde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:3bcf0edf6fe641ac74217e5894674a70f4f253bd5307ac1ff6c9752c31a98e7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:feb6f687d885ba798106da1763d591edbc9bef5c303f095527fda729c19a35b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:b0fffb686ec6fca6bc4413244cc55cff2dc50dc03f109f1af332407bd25b3d7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:7c3ba8138dba51c43e67a8d0020a18ae27d9d6ab8e30af59bb9a023a7fbc3be7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:da463fa423c5722e5fe6a2a90724c6c481a7df8f7d0f6b0f835f32a312042a2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:5b3fda00ec2e036928215a4d85136eaeae3f9ab3cafbca200690fe3d12492f12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:f7bdb2126274f84c0a968a1d545f035fbc6542fd51c8bcc92ce79283cbaf9c5b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:f2780d2eb4a0451a71672494328efdfc2a74509431c37ef0e631671c91479de2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:767934c37cc268f342d0835864f36ae0f9d284133a5234a8a0f26bf82273846f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a9e1f3ade8f4f2774ff96d9978457fe3b21b826a26bbacb4618f8549fef350e2