Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:d38b77d11f64540ed125cc8c2893855ec80a168cfcc5f565d0a278ad25e51bce

Manifest digest:

sha256:be8a40153e0b133e4870a59f039e1c0d5892d31ebc104779dc33b9e3e411dfac

Size

84.74 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:46de776e70b199ff57c60407531858dae973248047944b4c4fd2cda9b64cca12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:3e440c11ee4caa886862cc72268453f85c908249c936aec50eee8a131644b10b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:ebd28d60777a48666627face8eb9ac4d469544ce6f3ccf31456cfa3fa5d860b0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:5c5b760b5f0ddfbbc874e21c44ee9dd73608906e6780ac01e1950f6d8805d3dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:7e5d1f321d2f43066987c0e65053504a14d76264f80d98dd8ab26d6149b45dbf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:2f80a91ae93e86416b17d2dcf5af5cb27201088eb37507ec5b1f396a3d23d5de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:126a3519a8f47f04f9e3fa57a4e188b4aa7de51b5c6eb82aeda566734bd5400b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:dcb221ad5dd50bd2674cf384c703ab1af1ed62ec8ff1e121a81462824262f20d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:1d8baa3d872bde1010b107d0432e3426b091d7179e1d77f00043636661ef1aa0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:5a9b9049c24a35da49c8d4f2fd043bed78dfab9def7d7ab3cc43426cec5a0e1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:090fdcb2796cfce4abda7116df163ba57dc91d5a33f3bfc0700b6f5a7f45e3db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:599d68c2a9446e2b4f9acce4e17429ac6f75e01d5509e12bdc40920d3e278ed7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:594ba00b9a3ec1b9d147e2381df44e195da96d33208a408f5391be638dc21429
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:0ed66ad99062e05eb03ebd7d387b5c966f4db700d0429258e234e3f5764e631b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:14dcb5065e10a980847aac125c6508a7cbc1e0d9e80fc02e794fac833dc40a90