Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.29-debian-dev, 1.29-debian13-dev, 1.29-dev, 1.29.2-debian-dev, 1.29.2-debian13-dev, 1.29.2-dev

Index digest:

sha256:d4b1981d55c93cba50bf889205557b56ccf5d3c6fa187d327e3faac491f73b84

Manifest digest:

sha256:150dbcae0d2f5d7631f32d825d585e0315d84b45ae5489eba843de2c31989476

Size

85.09 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:5764d6a422ac7fee75be969c6436f40e1ddd758834d54c9f79bffb31694762e9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:9a5523bb9dbad139897274e4a25dad01700d9e6dfa1d68faa5e4bd549de88e2f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:b1525702dd97dfb97652eef306b8c33db44616d68890ebb7918d4af20890ca25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:33bba5e46ab3026ac5fc1dbedcbb9ada16f73d000b782d89ea42d2e02f285f23
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:005cfad2bd5bc4d273ab30720eb45bbd06678cfb0627b40a60503c9caa8576d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:d8329a9028261477871bc5c1b6522f0c3df81f7315fd39d4c4a2923fb465ee2d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:a43c3c795aa75e06542b828973d2e2060d6152582343702ad5aa9ed6119ed2ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e639f9bda2bbac502d25c9f31d97bc2a496e393d957c6ceed1f685f62079dafd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:e2a50c341c3aec071b542d3231d452771c8aa77a6859d2ee2adca0ce6ae232bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:9532c10a9591d1934c2bd1fa8fee33c3be6b8c5b5590d7c52d12af2212f68f95
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:0a1f935de89fd57794e238d1a09461b4362dd64285a1b284ad7c527e796baa4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:ad4635c27deee5939116d2443228cb3f12bc5fc8a1727289340b9ddf356c6188
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:cdfcc344d7aa221feb88cade905cf6ceb61a7794fd86009876ca74b92c2d6ae0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:957a2905c08753381ce1dbf9af283d0d6378cca1bcbd0c099530fc1219fa80ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:0fce2222ca33eb150021def6f4f771c95c8d134d1e63de08eac71af1ef4ef0e8