dhi.io/cloudnative-pg
1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev
sha256:061d7c4ce85cc6e49b073fc1d9b3723cbdc66d079b1c22416218f7d7ac0102d5
Manifest digest:sha256:2107db8496db6d17477c98e8aab5cf65a442341e7446b41c8ad615f41d51364a
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:b82ee4678b70de713c0f6aa016a0b836edcb004787f3644ab77ef6c199f37fbe |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:87ebe4b402bfccc63f71c5b89ef5862c32d1dee320149b6d31e1a142474b0265 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:d5c432061f7b464d7b33144c6a5131dc39d0b430fd5db905346dd328141b9c6e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:6bdf7cd0a63f96b37f8959e5060d00784191d444d1177f0a82ba9b1c992617bd |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:b8821744ce27e6ab40c05c3a6398a92d6bbd83674b91733fd5e37bca01b6b952 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:3e3c538e4edff43f1d7bd6585bcd9db4f0c6d8411717b3bea51f6b21025ff98c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:43bf077509f79833e46e846ee37edb3a625345ce2b0f544fc055063b2db78a18 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:619e44dab1bbdc237fc936f26e2c0702708ed8b45731e7d7866505b4a791478e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:f0ce4bce460f3f130d4e4fa4089d4128ba9beb56f80569de6c36b6c697e11608 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:e2c184c5901d4e3acd64bee26f4595f1d578f011f815f9c5154b39bdeb8639ff |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:8fc4984b493bbd4fcfa6d20da4beebfa762bebef8734d6ed92735a5c3192a278 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:34b8900f23b3f92b418c9b77227a096e83b3f62f38e2d66b82ecba99b6f78eef |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:90790bae683793b673085a8928fd3fb87df9ac4ba6c7586f6aa4575e40f18391 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:87bc42eeb042d1f231285c006c88c92bb779dd207ba718a83cc375c04912a1f1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:9ea526fb224afd71442262b1121b3ae98a212fffd777ce9cc2e08e602396ee76 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:8eeb85436fa06d59af84e3a61a4da798272388fb8c114e79d601ad96942db333 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:01e967934a4453e93acb1750f7258bc0aacc48dcb59c63994bc610e2a8370dc2 |