dhi.io/cloudnative-pg
1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev
sha256:a55dbfacf79260d270afa3de19a3bc4da6b7dc5b603dd334356b93f37543b12e
Manifest digest:sha256:0fd774c7852f7ce1737ad3b2e60b12c51b2c6f0b513cfda5d8cbc1f1b9c56fe0
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:501f24e1e6353dd131aa0efa67f5e15c30862a54e41b8abbc06f6a49d14a1700 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:03b0680130f2ac969db204612c1bc898b1569a512418ec07d68475eafce2b72a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:473fd3b59971e963c8107a078e5c87f09db37a1d1bc73bdda929aaffb122d917 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:0e8f23ce8972936d4d14f7b666d95f1d9c20decfbc5490ecffc9b6dbe0e85858 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:6110ece789c1db6a1355a34937846304bdead45423ac1aea69cff618fa583aa6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:e12e5c367d385e8840df00af7dbe8e3b9cef2e78b3a96f9cdcad053975325b7c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:07ac826072fa43fc60ce68cf35db080e3d22dc6433630ea9edf6f0041e15e254 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:48e75b94fd4048f54e22c2a285b35322439a77e236ad4904cf3a59a252cffc3f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:43df5eca28af77f4b485caacdbe660c368ea14aec674bff9b0bee9b3d753b70a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:b0c6370c3d3ff3b33eb4bd113208c0f87e82510376ce85d940cee1b4e350fe89 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:ed774f5224f607ee55286993d1b3ddd1bec28772db93b59bd707a6d51ede2d2a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:c6e5b9e61c1cffc52ed7eb347a776d854ec0eb838cb5d666d1d1c351fd6c044a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:f098b5af2e9092c03516f3f5efd0e06dbfd01487e87b268038870b486feb3dd7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:7eec9b2c01f6661e3d468a477e2cfe534eef8ae10fcd9fdd993aaeef1d03a2d1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:d11f8bac9b739af78bd9ea01b133dd524313d1291f8db7a6b7aff51a2707cff1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:8ed9a1b81d4e462c627c6c38402257a07368f79a2138a1d25ad806ae20cd5cb1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:d6eb84555ca224abe08d9fce9f2677513c9c7dca0e4d7bfcb69ee9f801b1ce25 |