Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.32-debian-fips, 8.0.32-debian13-fips, 8.0.32-fips

Index digest:

sha256:3a847c1388f5e84bb31ecf110a66ea08828a9f70595cfc61fa037d2bfdc7f881

Manifest digest:

sha256:22c10204c3306cb92c002dd77cf5faa4eb51ceecb1ba998fc2b1a216ee59acb6

Size

63.87 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:0a3839f82f626d6e5c48f440312732277205b359818031096489e0926631bc80
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:cfc55d42444c129c665051049af25616535cddd2fb7456a84e246294fcbdc1a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mongodb@sha256:1526e8618608a02b8388a94faf6d12d66cbe8ddd83623146a217ced3cfa51266
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:602a4220bd8f3f935129caa76f96a6351b3b13bc220c13e9999ace93d5cd47ac
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mongodb@sha256:c8bc65f252a302ceaf0ea431cb827603bd5b8e5aaabcd6d32d395db604b304ee
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:cf92e7ea60e7d4378bb88c7bdf482c6c1a2f76cf1a7f0240f31c9aa1e79b9b03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:e0e037cb0e9e169d670bd86a7b34220276633ac7a5689ab128b057e569507ba1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:657e22e85ff996918019eb309feae5417fd1a3a58e81f96110449cee3829eb45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:db9b70fb6bad792d9df3ed6cb40915ddf811dfc4565218b3ecc4b0cf3adb334a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:155cdbcfca70b95c7bc743737f5e5fe2719652939b68753b32e50e0eb251a007
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:e514266400831d06488d6c36a9ee39a945d0a233cabef84d0a7589c7180a331c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:877bf1068f15638e23a7b2803bd25971b3abf7021c772fe2c45fc253750321eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:e1ff3b63613027a159bf3e3c27891d69f61bc418f600fabed235a4d8e70d6a43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:ec883e6196b00ef24d2b46a09ca2fbe6a6fb4b0c4385d75aa321cb458c07aac5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:a232d0b3085abd68146589f1c49f45881ddcd1e1e6489d94bd267bcf776918c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:d6e69c265f02b29bed7e604b97935df17ae4b8cd304cb98745147f22f17b8162
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:2cfe6c6a2cb1feb8c502ba51960fe655b34055b63ee21ab94ea6c5b6bcb14d06