Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:36b9f904749c4f2af3c33aa6953918ceddd6dbb6a0c8bb8f3e1ab7f5ca057d1f

Manifest digest:

sha256:b0389ca91db90cd1e1fd8b0be016f19e0c32880e1659eb773c5c870b03021785

Size

174.60 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:dc07f74e5e574756666b6fd6f7860935e41637dcdac23bd40a9624c531784748
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:7ed12e740e66200d655b39806c249d6b01d81af2f89d455e2c53de962263ccdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:fc8f16433f0b0263c402f09cc700192838d745036ea2cad83ebc0b001b3b21e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:4d39b76add6c3b12b0f78e6048a2d0447e6396a6bfd4205bfa31c3f89709e0f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:2c660f61a7849e721c521dec189b4440604f42725165c776d1e279596325d34f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:82418d29e39716327c15341bb283b638d9e8e30856e97d6020b3430ca0d468f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:58f7fa64b711db5f2eeee7ef5972e82d3fc10e560359a744050fc666819d0d1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:575c6d5ff9c6a36267a014c4b6dd934b6f372712104ff13651b347c4bb60da17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:4d808a83b051b36a48690b68279da508e25bf6d9741b4a24f2bcfa706e50375b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:7b19fe1968af0d521601fde316beeef8ce788054c861c6a63f39ea455aa26085
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:69a5c21d59ada694f533477bb471fb7365c0a3a772ab763ba086aad6f13a1abd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:58a67c5ec754fd0d47b047aaeb383faf308f4e557b8b6094f03854c497c9999c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:a8e4e9b1db42ee381e612ee880262ff757e84023c594f8e73ae42341116b22ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:4e4de05a12069b81117fdedbf1693c26215ba0e35840c4c0752570c88e746516
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:269e5baf67d780989ed56c4c903486feb2d7a80e623b1bb3d83633ee6f97974a