Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.29-debian-dev, 1.29-debian13-dev, 1.29-dev, 1.29.2-debian-dev, 1.29.2-debian13-dev, 1.29.2-dev

Index digest:

sha256:124c6766e597e99a3e45aaf26439c38a7b8866766af67b47a24f2b4272438c61

Manifest digest:

sha256:254b5cc261925e6f157275d6ccd8d6c0efea6619dd45ededf464827cbdf4f5f2

Size

85.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:4be7b6122b2a8c035247f4dc247e542c160c60f7af86820cb8f16f0a564068a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:73b113ceb0a38e40025f4ef1e54075773880824b5a8747937bff8ffd8c8a7f70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:b53abf5b6ac6b7e13753adad1f1c57ef6270f4d4e597ad90ef6613ffdb3d276b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:440e9b8c60574ae8f51bfa3fec65cb0b350d33c1b25e17d2da15083262e108de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:0f2a715ddf3a2db54b1b4140ff21d66c8d8c33ee6518138d14661b95c207f7c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:7a8ea42633c90f8b2acb5677bcbdf37677432a3f0936af46b5f581750399f024
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:a70db74726aa452361a0f6389835a9e02be22a179e7c3fb71b58a3cbb13f9522
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:71e69ce345469bff32cf938a9e3076db7503f09f8492c804d804a9e5681d41a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:ee7ccd541eff24284a5995b19ff4371130c952cc26d82dc36890ed3ae6ca2fd7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:3ac87123e231c532247fd13ae87ec15a774cafe580440aecbd494ae529412c22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:5388114c27f34c71469d9c05084d7aaeeaf7e0ffba61503b6ee170f790448992
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:fb7cbef6448a6950d1ee33e7178b3fe9267068f7fb0ffa93a6cd755704e95a68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:43b88decc7b8b3fc7249c44b85be7180368eec80b4b9a4f6fec2dcafb244cd78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:bcf8c8d3fd4d1b23128c7f14d6b5b07738e3f1027f9c373a0339f18364f8c096
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:a7a04f023557e98522e7bb2ac10f1202b5210bcf12a527383e7661805d60b03d