dhi.io/cloudnative-pg
1.29-debian-dev, 1.29-debian13-dev, 1.29-dev, 1.29.2-debian-dev, 1.29.2-debian13-dev, 1.29.2-dev
sha256:124c6766e597e99a3e45aaf26439c38a7b8866766af67b47a24f2b4272438c61
Manifest digest:sha256:254b5cc261925e6f157275d6ccd8d6c0efea6619dd45ededf464827cbdf4f5f2
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.29-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:4be7b6122b2a8c035247f4dc247e542c160c60f7af86820cb8f16f0a564068a9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:73b113ceb0a38e40025f4ef1e54075773880824b5a8747937bff8ffd8c8a7f70 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:b53abf5b6ac6b7e13753adad1f1c57ef6270f4d4e597ad90ef6613ffdb3d276b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:440e9b8c60574ae8f51bfa3fec65cb0b350d33c1b25e17d2da15083262e108de |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:0f2a715ddf3a2db54b1b4140ff21d66c8d8c33ee6518138d14661b95c207f7c3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:7a8ea42633c90f8b2acb5677bcbdf37677432a3f0936af46b5f581750399f024 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:a70db74726aa452361a0f6389835a9e02be22a179e7c3fb71b58a3cbb13f9522 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:71e69ce345469bff32cf938a9e3076db7503f09f8492c804d804a9e5681d41a9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:ee7ccd541eff24284a5995b19ff4371130c952cc26d82dc36890ed3ae6ca2fd7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:3ac87123e231c532247fd13ae87ec15a774cafe580440aecbd494ae529412c22 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:5388114c27f34c71469d9c05084d7aaeeaf7e0ffba61503b6ee170f790448992 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:fb7cbef6448a6950d1ee33e7178b3fe9267068f7fb0ffa93a6cd755704e95a68 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:43b88decc7b8b3fc7249c44b85be7180368eec80b4b9a4f6fec2dcafb244cd78 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:bcf8c8d3fd4d1b23128c7f14d6b5b07738e3f1027f9c373a0339f18364f8c096 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:a7a04f023557e98522e7bb2ac10f1202b5210bcf12a527383e7661805d60b03d |