Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.0-debian-dev, 1.30.0-debian13-dev, 1.30.0-dev

Index digest:

sha256:412b3842b0d8bf64c465460732b5c830d22b7d004d8bf4123b1457881d76b66c

Manifest digest:

sha256:9a508822a6190cfedc76002f34e72567d1ae363593589748e3061b976e0ad415

Size

85.38 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:3397a5acbf17162cc33aa2c72a3a0a649879ca579327217175d99d62c3dec692
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:e7ebffac5b34cfd4ef35f61343b34324b2e74561aac94ea9d1106fa9db75b234
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:cb12766a95a5f15f4f0deb23c5c0b4781617d2692e5307046b8c6e70f6f96b28
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:a2d4d68fa4671793c43fa321edb7217a5fd560fef77d29952e97d076335cd05d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:5c94c3a59d29ca5c63dbea0fb21a5f2f0a0c3d853f225b13495ce4c2f0b17a33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:c21a10f5b7e8d3d2f326ce7bb5f171d5f1be3ff936e65ec7723692d4b9697190
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:729299398f9a90005dbcc74e778561b32c7c148426c5040af32906d726cd0bd2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:4443d6163230e12fa25b0373f64d79f032d4c97d2bff0a47c1f5c36aa5f608b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:29c8e29aef4980e9c5fcc557c294e1a818f5e424bbd9e55608e8d79fb8853495
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:0d90a678f23c3a346d95d3a0644e73dd4eee7ff0c7e43e662e6f72c081b3ae71
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:38d25d7b8942dcae08d935b74652f727dbbff7ab3f00cf4cd69536335ae62b74
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:ea6c8bc8d61e157a0253fe32601e4d5fac845fca6c79fe99ca0aed35c7443070
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:f6e3271fa6cf511b792c833697c2d2dce3c45fec699c8e1914b3c7843212d658
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:e185501dc80c1b4bb0d8a7d1400deba658db4b17a80bdbeb580c9084783efda4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:0c8e0c382d4c08d4f6d1543aef2d49dd147b044d4ba92f7847e85060b1d14e1c