Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.0-debian-dev, 1.30.0-debian13-dev, 1.30.0-dev

Index digest:

sha256:a8f8e8bfd44c7d59d4aa864e59c257f7ddc1769afd83b8169e309d33a12d1c72

Manifest digest:

sha256:54f865ee468732606841f20c4a0e80b6437db8d9b68b02652f94fa4b97b2f7c0

Size

85.37 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:5305430ab683338097424d18c1d87e3c1e3f641e6dca867ece280c1e086fda74
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:cf153cfc7c92bbd14329027af7ae48f96a6866313c52eebeb052bd86fa7971b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:9165c5a8882d2f9c4b846846414f933287ec76697ab6b30ca2c66abfa89d4abd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:e98f3cc8d8e774d8cd8f1066f3e47992aecba915071099201e18e3d8c91dcd0a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:3c94d4fe8bde408733cafdcc7b7f98d56b40c5bf136657d4e5a0c2bab893e8e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:dd150f2a6f99b448510b7f8ecefac8109ba17fc4523f4ebd8ad7b2710acd1dba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:4de5a16fc4e524b7d31c25021b56a60a66750e3f8f3c15a660ae813fe048b38b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:5d2cf44fce1922255e67bffd86915420d73422da1472fdbe1e900a3d6c8db672
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:e723131c9a3edbbf1eef05832a61f960aa8622553e97338e31195dd6e1ed1559
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:17bdac27f2b3b9912b207f1c2eb5ac06f7496348863c4f1eb92f43b2c0870c27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:9c2d9fb5f3dea54c886069644da21de2ea65372689508c7589986a2d756e9e27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:9dc1d2959ade56ea956f41b1f4f9f498d1d056120d05bf5da21a850a1cd10b41
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:f46a901f80ad10ad2515c2ee00af0c04401d054daf7f553348ecab99720d41ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:3c676e9ca99882e7cbe418ebb0b58c7932829df0b6512a61b893a4944406aa66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:45a42259c02caefd9e9e27e3fb856428e4b049b560b2998768bc36006bf44c07