dhi.io/cloudnative-pg
1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.2-debian-fips-dev, 1.29.2-debian13-fips-dev, 1.29.2-fips-dev
sha256:3bccc58bf8a472ea49f1e4a0fcabcc2bfd4a556ff3afdbeb7b817299a6bffb1e
Manifest digest:sha256:f783ccfb8bc9b913fa435fa7f3426a127bbb0a4348faa617c0a9458145ffb9b7
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:e88e1714e5933ca5a31391a9bbfaf88d66952d1d06c63ac431dbc0427f4871d1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:59ac334f88cd0aa48f06281800e70af515aef7aab5990895b603aeae388553ab |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:b75926fe6b56ac29e098e58ec315e49baa099f0fe72f22449caa629c0fb35dfc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:24674b652e450a27c31b1d5524b93e5294b2394db6b33e7d1c6774d59b730fb2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:9eb6cb4b3602216a4d85b17eed61b671f45c621c72535a6c3fcceb2d8dac1eeb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:b7ddae1aa0a7d5e0b4a76742049a6872e9657394d81ca78d2332544c9a69783c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:1df018404993e71fbf57526c89ea90ca2bb4110c203b613daf3ccef2fd273225 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:d56a51a3237cb83fae00165021de3c9a1a3fdedc264ae3f8fa105d6c177a39d7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:086b0e2ac19c6f087de645baff42c851fce3fd8838d02295bc2c773eaee718d1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:28996b9f16cac7e0d4042d62509b0228510d91c37946a97aceb4d0055fa2111f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:ec541bffd14a7b5c3f01d3eaf18459768be4dfa64967e45bb994e53e84c0c2e3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:c00b5d132658ce13b17c87ba5cbb13fec8e28a2b75d1146da7b545f029e5e28d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:45c66175decc7412c1951c61a985cac2eff2e8c597519834ee1792dd19790a74 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:b3f984b051e45852c59448f799399eb2b682667b4576bb51765e4226927aee7b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:a458018c0f9081fc52c09f22a198afd1ae2dbcab610bc9f262934171b3a309bb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:30690d4614a955cf739f3092905d85a1b503975723ec2639923661e009b0515c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:a0704dccf4e6c2eff124da39599c9f6932db9f8c209bcf012095117a88a2b600 |