Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.29-debian-dev, 1.29-debian13-dev, 1.29-dev, 1.29.3-debian-dev, 1.29.3-debian13-dev, 1.29.3-dev

Index digest:

sha256:dc57ed2752f45bd3789ca50029ff95a56cd32dfb0e5358ccac60c39a042b87b6

Manifest digest:

sha256:b6345623e56c25c63659808ad2bf716eb685a20c69d6c6f1e09140612b2515fc

Size

88.88 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:607975774e6dd2124895b581c76230b2d24a9e1a47c52fa6dd3ff8906db26cf0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:73cdcb92c69e37ed9846a13282082de8c0aad22acb53f68bbad68a0a21be0314
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:cb64356126fc9371a9d2f2ac321bc53a4834849fdde3a4511ce42d1f89669b2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:baddd3db12966304a02ab1b72629914d04b67d37e1e030c92c4fc49099970def
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:6c85d80d1096648ec528fba0708d109ab3d7d86b0948ec2a1adc7e1a25a2a157
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:725839f272dec6600e31273d7dec341b9b6f1ca6d74a30b5b820ead73ba6f0b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:04164dde3dac4f29c0c703c607c6c81c1a5bc6fc186231ff3188fd4352a9c765
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:9ef6e49632e4dc5921a3fd5641918921c5034a6d6b722a3fc27b623f318d98cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:c2724b4eb5b8978839bb3db2fa26c425206aa6d157c1f59aadf58ee4238c26e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:1a7618066d94b68df1b5793ce39448b309ba829f96ab85a380e0344ac5dbc98c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:fdb4e5967db163e1ba9b7dae5aa0ae24d392e9ddf546e835c5b93050ca915600
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:04e2634467f07406047da1aabc3a5df5edb416915f0672635c6015e4fd0b9a03
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:0a4538e536fbb5de6fce88892c2803ce508ed8ce889eb73a304c7e79e8bf8089
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:083124a2fbc542a911051d7fb892591186bd5ee28f108c974a2c9672b2e4bf23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:2db92bd3f447a6ac633a0cff052e532ebde6d36696b56b5fcb629989e6f2bcb1