dhi.io/cloudnative-pg
1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips
sha256:0f72b996891cae4990a80abb82c38897bd3829070efe1c6ca479f85fa9033eae
Manifest digest:sha256:4201083d52bdb8451e6bea9e67e97be5a6dcf5faa67c2cc6d417b0749db8377b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:c0e3078c2b440782cb8fafb244e08a70dc09cfccaacfa5118dba191c01f2929a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:ab5e4472e141abc4f168a94df54f9ac19e389e72aa05d80dc18ebc5a6c33ca7a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:593480df1415d2e598ea98649809b04e08293501b3a72b9e3437f41f0dbc1314 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:ff941623f4ba818217977b438f5f3b652461f54f8cce33b15c17bf6ccf5f2544 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:740819af969fe89c84fa030569506be96ac5f21384f9aa77db4fb1922fc09568 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:7e0542fe35c4e4f8c14398d71edb7a702de43ff018dcb7ed11a99dcaf41f011f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:c16f16ff333b1a26e492ab9a0877a10456bfc65e206aeb23d18d64ee3db782b7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:e52a3d4037435b94db17f4ea51217dc841ddfb6e393d1bcf538c79b972339aa1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:9e5363f91b08faadab2c9de71c1885ad2761f7ff83fd7d74d5a55b43e6c4d76b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:2999b1c3855dfc42ba8eaa0d515d1f5484882893e8631072a27202ff850975ed |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:89828e41866dfcf1ea6b3faa52c943f04ac938e90e548a542ef46441b5004af9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:0f2ac46abd2edc70fe5813b33f359f3b808f7e4535f663e88ed4fdcd457e4628 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:15358e7ec75a7cd6cedfcce43f44d6251d09185dd976fd25e33d183f04b8e504 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:713d801d56c1d4c890a2e4240cf74e90321a76019bd61bceda9ffc43900c6f66 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:bfe41625fb042ebc095bbfda7d8500fab464f3fca7b1715d91b3a9bf1bf4cd4f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:01d9ca078b154f101121d59bc378ea0c3858daddfbbacc06d22a95b0c3e4c1f1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:5f64a62d78d9975168327fe3081228db4ca857753a8c5580a5c6eefc1c31bc10 |