Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.3, 8.3-debian, 8.3-debian13, 8.3.11, 8.3.11-debian, 8.3.11-debian13

Index digest:

sha256:1fab4f0b46c51d51c28a6b465224e21211df1e983b8e191732510ac907b89f3d

Manifest digest:

sha256:518262ac4699f869027647bb2d8610ded35b6d69b20ebc97ccf1921a501cc3da

Size

56.92 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:d12cb2f882022982ffb8b8e8848a6dd685e78dccf656e5b4f15cfe7948f66202
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:53ce5b5a50426634d9ef4fba7dd7d3d8d10e38a07883a1d0853f63a74ab576e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:aca8570a5c88ceba6e1dcbe83ce9e69725483b86ed772d612f65d679b1bf5b17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b774220a2974d6c6a61b9a75fe0341216ed9e13385e33ba2f138792944802efd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:fdffff8fa4dc79f93fc055c04dbc9f96d690580e1ce1cce999dde84022d3975b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:ea2fc9b38a1c2d9eeec68792bfdc735877086c8daaba88e7a6056977bfc4a61f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:743d4523f4afdaf1f89f2908eac783d5c08ac52979a15510f32b00e0ec71789a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:03d8f233c32f346aa11a2f2647eca380bc2f3e9356c45d2242185056111b5e68
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:9271cf4d22b5de6aafd4ed92d12d91f2cdd96d7bc423b6f80c1f9c4738a59f3f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:274051af5d1d9f803bebb751bd4b22e9ee509e4c1a0d80542091cffa896b504d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:575144045986c8d8a8b64cf08ff7d7c5c3a7e25f86d467d0ebc898262fabc3ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:fc02a0e9cdadaed2bda325d11fa38b95c79310730069181c797fb94e4d9f6580
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:3733a6f752bc67506a7970329531ea08d7cd7f7dad7620821468abb2c89af44b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:870c58d0a7dc6960e6c8208228bab5645e1df23d2c4672a555da6a5f46c596fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:957c0fe82366e543ff2a60931c75d10a0520d3f1cd208baadf84837a0326cd91