dhi.io/cloudnative-pg
1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev
sha256:47b3d29872f7572e08d5c9dd716fe3dc344c15c7f9531f96400ad1c53eeee24f
Manifest digest:sha256:48f54195c716b345c78a45b5341d4b35651bab25251446d2284e8a50c67e27e3
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:ae261fe5724f003a16fdafba3f29d9b8783df3eff8f99aa116850855f124b1bf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:0c4b9e056c893e723ea21b03fca3382e2b53d447726ed06b98ca6db8094775df |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:243cd37ddd9716eabba4edccf1bbefed2860655ceb9d86b8a899183b62b94448 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:fefa7baa4ac7f606ccb6631443494b6ee6aed84d624b693d0d2663ca1dce2957 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:9074e9216b6d6ac0be9b25e8eb26c203b0f55d1a59a5d6e3d0e95ddf96de1ce8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:c9c214046c9046000c5173dce71b8eda732e536965b876c8ad6b3b0f47cb2565 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:8dc10f3073a272a776eabc56a1b5af8ad5cf50305ecd57b512f7f7755fc93ddb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:c3153df5043ee4c21514b4fa3c94bed7087d694eb4c4d3ce66f408f11ddabf60 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:f8abcf01d3c23f2cbce815838fbf6531979814af807623d336c9711f7294739a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:cee9ff71f949871188d9de71904bbfc5d9e2ebcf75bc9b9173c4ec79d73e52c8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:4f979b92b977face83f10c79bc353e934dc8d6b3dc208a2388b1f8cdab7d3139 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:b4c76cbbadf166a8b3a6928f6a1327e9359e690d63dff37d56306e387eb7ba6d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:d39191297fe345026823199a2070dd798584c08cda609cd6d582e018c45bbafa |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:f545ef0e1eeda0e7ceca182aa73e6c20947ef4fe123ec8cc6674d224397f6d66 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:a579d0ef0a442d22cff186edf6dd92b9af213a90ea9437aa4acacbc0f27ac92a |