dhi.io/cloudnative-pg
1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips
sha256:672ea8fd20067ecc5e65ceb359cc793721e2667d5ed4325dae0fa82224058fde
Manifest digest:sha256:86e6c40b0dfa407f19d9d5a5f56dfff92cbef4cb81b24b1a2988604b977ad0f4
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:98c5900ff32bc6f5be0d82027df31c1720d8529fa3b5d32d1539ce791de5fa67 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:e5c5856b6832473e0536a1ad3b73c0a60f053ac988652ec0c473688c9ec8d00b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:6f2bfd43998302c213921d55f6a1c553f3821570ade256a911485726666a931a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:90b641eea8dd80e6202c87a5fcebfa6d9953a2b3fa3caaa8e914bb79fe96c3cd |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:205b3f47ed40ed0bd868fd78997ccc2cb21209685dcd7e2a41a0e68362446a90 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:0f1e5868aae14ada939c53b72eea0aac55cfdb1a05f4df71633e75bef3079700 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:f721bb61ad122be7e3970ef613c7583029e99ae192dee2cceecac064e7081974 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:3d6bb3ff4ea033976cca9a56c226a003189b475005b507388990ff6d15c27bea |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:9a7e2a30c544a2b2f6c81443666354128cfc1710c0084da3edb65337116c9af2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:4dd1c8dc61cc510f38a4d1228046ff044ca58718c656971f96e7276bedf3ea7d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:558b9a2532e1144e118bc0ff8a9bb3c0bcb6cfb4ffa5f77993a84b96cbf92b6f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:948defcda4e9118b57acd3388c4b1b6cf3e90b77a17950873bb140082f2853e5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:d5309d8f300747724042d1d8638ac0e04a80aa7cbf7160599c49104c39324a50 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:4837247868d0e17f97ad4a8aac19881473cd49c3e2cf91445d5c3083312f1ed0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:1bcdf78bdb9a13218a0fa5dcc0d6cc127ac4755e6ca98d2d3257e6672e0e2269 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:fd001d167e3d1e8e419ded52f24353e5e5bad7c0177d624194d0b534de20dae6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:c581e56de2ef3ed0e1fdcb2f524047a30eaff1bce64388b71ce730bda32b4f16 |