Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:3f1c3afcc756e6dde4065270f775ef0c34ee6747c0cb829b5a1495b4896fcbed

Manifest digest:

sha256:0b05de22ae0a7a219f1b078501b987e38e9b40d91eb334d65abc68d840180baf

Size

84.74 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:056e66befb8bdcfabf9b12f81daba444935825a94285afe849994d8b3e237c8a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:a9b395975c223839a64fb481e3d32ec5bd6eccd7dbc8e1b7fe8e8e4683971b39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:75c8ee72f001ba005aaeaffc64f75e1b0cdd26bb800d01951e57d66db5411d0c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:85d98452a9e5b5b7fee37092917419d5a8def6803b2310d25f9df89a93cc5757
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:c8a7c7e365cc091fe82b616fa7e6e8068858f4090c72736e288e1d0764ed6607
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:d4f3a56b3d2e1b4fa26b7a12943b53b18b4e28ba7302a503b491ba215003a6ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:fd2ad30a3c55b19857e1c877d1365669749135a5a95d085b913d5d530f462391
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:19de8385d8a38ecdd3085bc9886f3de8ead0a4a2d76e052c26ecd3e2f9eaaf28
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:204dd24213521bcde10ca8b5c8f3a0b1181b343f5ee29000c63c27f8839c0db0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:d818eb554515e33f94e237df86ebbff0b444590a077e9324b376a0764ceefa1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:0114ef6b3bc9bb77bba0f8dc2a5b180c809fab86fd93a495696786feba7167bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:8595d6674689bd4302745f7950a7714ed9b5ed1ee4e244f8fc01ba4cf94e8d2f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:94373d0b32010f0a0f66223bdb2f7c3647943d5bd58ce0f7eb2bdff268d301d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:4eb23c9f6aae62971b0cd3ded286410a24c5e0ed925635b040f40eaaf7ef9fd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:45a6da4b9f100eae389ca0465ec55bd6b90bc7465bfe23f673c3b38a629597c3