Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x

CIS
linux/amd64
debian 13
Tags:

1.27, 1.27-debian, 1.27-debian13, 1.27.4, 1.27.4-debian, 1.27.4-debian13

Index digest:

sha256:d4f8311c6e3ac409ebc572933b0946142d3fd59248171acac0431f6fb7bcd358

Manifest digest:

sha256:a71daed04a4fb688063b262c486f2e2ed1566dc41f5ffb2af40a1b6397e778d6

Size

30.61 MB

Last pushed

8 days ago

Vulnerabilities

1
0
0
0
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:130fdea53d716fb9f9354735b0e67ae1894b27752fcb9972e3d8aa2b6b8fffd6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:153c2187069198a26cfc2f2ab1e9b7d8474aa7418d6d3a1f8af66b289c6c1b54
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:70fe0b57c2d3177e956f79dc27f8451db27df2d7606237e8535aedb717d0aa06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:4cf19c703fa54ae0f402748f32a5f7ddac8b9570b36cd6874f01cd278a10223a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:ea88265f1ceb9f90f9a608e2972059ef1750460610a239d8a9e4fac538c634bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:c1e48fb93a91ae6e26b6e6dfa76c40bdfc1af4cc038fa31f2c76093b9906287b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:c7c260b70bb3e13a33e0bd4241223fb5abf52b434e7c2775f2ddb98e290f2f61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:262a9fbf6bb0133f7999067d2a98c8e552239d2d6624d06d5d9d099782d24ebb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:0951cc9a1f772c767b8049b8547ff0e92888bb5de8d9d030176a9dd9cfda51eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:a0617b95dc267b04682a9a9e88a0cf5edb84972fc74942918f05881aa0d0c2de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:84b71f805077460a65f41404b5cca14e9d0d9793a68486b9d88287dfd4122202
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:0c1bdcf93c1874c7bf46c1e6bfd1bb3f55e61a7bc5a1cee8f76381e0b232c305
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:610d66bc514f0d09e4aca615b6615a53f99ee7bc905b0dd9c47c46afd01a2023
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:ca5cc64d641492ad64ef3bf59d6dd804870fa74440ee336d22fe22844d6730f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:db416f8eaf0a4bbbe8119ade766c64ca2c9d29f6d674b27585c822d84c78f367