Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:47b3d29872f7572e08d5c9dd716fe3dc344c15c7f9531f96400ad1c53eeee24f

Manifest digest:

sha256:48f54195c716b345c78a45b5341d4b35651bab25251446d2284e8a50c67e27e3

Size

84.73 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:ae261fe5724f003a16fdafba3f29d9b8783df3eff8f99aa116850855f124b1bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:0c4b9e056c893e723ea21b03fca3382e2b53d447726ed06b98ca6db8094775df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:243cd37ddd9716eabba4edccf1bbefed2860655ceb9d86b8a899183b62b94448
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:fefa7baa4ac7f606ccb6631443494b6ee6aed84d624b693d0d2663ca1dce2957
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:9074e9216b6d6ac0be9b25e8eb26c203b0f55d1a59a5d6e3d0e95ddf96de1ce8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:c9c214046c9046000c5173dce71b8eda732e536965b876c8ad6b3b0f47cb2565
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:8dc10f3073a272a776eabc56a1b5af8ad5cf50305ecd57b512f7f7755fc93ddb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:c3153df5043ee4c21514b4fa3c94bed7087d694eb4c4d3ce66f408f11ddabf60
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:f8abcf01d3c23f2cbce815838fbf6531979814af807623d336c9711f7294739a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:cee9ff71f949871188d9de71904bbfc5d9e2ebcf75bc9b9173c4ec79d73e52c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:4f979b92b977face83f10c79bc353e934dc8d6b3dc208a2388b1f8cdab7d3139
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:b4c76cbbadf166a8b3a6928f6a1327e9359e690d63dff37d56306e387eb7ba6d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:d39191297fe345026823199a2070dd798584c08cda609cd6d582e018c45bbafa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:f545ef0e1eeda0e7ceca182aa73e6c20947ef4fe123ec8cc6674d224397f6d66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:a579d0ef0a442d22cff186edf6dd92b9af213a90ea9437aa4acacbc0f27ac92a