Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.11-debian-dev, 8.3.11-debian13-dev, 8.3.11-dev

Index digest:

sha256:a5a7e61b4d11210f40d6e26b480878c9483a6b4b93056d8d4e80f278dc278288

Manifest digest:

sha256:a725e65cc80369ae54ddf977970c913bd8950af76c7449e2b2ed367ffc0d5e27

Size

184.93 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:0e6c872df3a6e36685c37e42bb7e58225c9efd1c6bc719737ba207dc5cfdcbf4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:00fed0828bae0acc60456f2d6373cd74caf671f883b30c63a4543ccacb474e0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:320f9a628a0fab0d3d8246b70fa986ae3065aea3e3b3c49b4bef36b84fded1c1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:957369d3b638e5f7ebb7afbb112c27024036c9707c7c42a968f7ba3bee15205e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:5a95f96d5d4c42bc442a411dde5d24566516358a52a5170a92964ac62d863bd3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:1bb253f78131d58ae18b551deb3fa8aff5281175b6ef68289a5f241e2e744290
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:f878b1fe71327d27b698019995e952e7909d7cb37c6b5543679b0d7ce5c222d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:38bda2cfe18744bb06769df0235e40f6037f81ad59b900981df6d80a0eab84cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:5070959cf6c1d52729c687e7ea1b5fa0e3acba59e99aa9af8a022f6b6b9ba36f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:bc636f1d4250c9fcf1cff77a7eab944a793662b191ccca7617b97b1b0511dc96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:9071f3430cbc840bdebdffba7f87d774aebdd6c893ce6fb06997d0669a6f3784
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:7f1398777de9db694e2d38da2ad3fec4ed298ba51299c75a8819aff0b1ec4820
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:42821f0e329f0d70862289356463c3a0f0034cb4f745d786df37af9564527d73
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:cdcf1e4acc8c5b298ee26cbbe5850ca3b1a47b114c3e8c41862fcc03513b9370
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:46e6023962af487130d60616ead04d4f5355beec22457aad906e7bd48f85df1b