Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:c8e372203025b69c2fc3c8933a85854e601ebbf7a88da918bff7e07838599d5b

Manifest digest:

sha256:8b4f863e8384748b22de49ee31f902b8769c455cfc83c8a77bdd03092581d896

Size

84.74 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:1f887da10287d90169659de6d91c999cb8747dd116a99a68fbec2889d9f7a267
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:595a20fce8b67ffed57f18762413eb72b7f7dfbebf3dbaef28c29049d4915b74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:3a43b960521c511e65075abadbee91273f870486483e9a08d8c4dab30470268c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:3dda0926d5083e289025188557b259215409daaa758380af0201e253c7756352
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:ed8ccc1617e35b3d1e4b8f3121116d6e092f5356f316bb3ed2831a72beb0b2db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:79660a6a80900111c8067ae01fdbed6df8e328587c7f09587230309227597d2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:d2c29526e64f622655055d0930eca5704d31165444807ec1c117436662ac5a1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:01aeb76b431f70cf12139fbcd5135a3e97c3aa9a30a84d1ec35dbcc6c951fca4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:05262bc792686f03fcd59dee2d6314b7c69b7c6010dc2bc939671aef2d823231
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:acf548fb7c1d9d086b61a96608b7b0d7a8cd437e21bd89d06b0558f3c3893d9f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:71c51bbc0113a1455a38ca09d866046364b2fb4dee79d20d141097ab00fef625
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:d237bba78c9b20a65008d165bb5969a09af8a02de1f9d0a0cb22664401106bb2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:ba70d6cc9dbdfd0347389b7fefd1f075ed243866d027ef0bcab1c97c22dfd8a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:e7715bce4a4fc531dae608d1f4adba96bd257164ac5d7e430c96ad1b9ea7efb7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:895c9046634ddf2a919fd309cf03d57bc4a633e715836c04026612728471c70b