Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:4aa97a67c7c9a904edc4c5b6e5f3932ae9a691c16068151678421e3eaa87e8d7

Manifest digest:

sha256:c7ae7b897e824648113503a6fd7b0ea686f76438a5aab0d1b4e6891b9610cc43

Size

84.73 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:0a6cf3153726b0a108b3dfdd7ed9baccbde329f26574f8c34f41fc18ee94298b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:436c9e52c5355a8ce0372ed8b4300bf01e652e0912f26bbd77d7f3952ab7d299
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:fed6cd4a7bc5f22746c4ce6ad439b4ae062b27709fbac18203ff3a733fff966d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:c6f57ee9afa2e7393ef5c1d911a8132605ea86eba4c65ce91048c187ad9d444f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:455953036e0bae46bbb1a7c1194fb86fd396dffba3025b33affdbed2ae216d8c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:04fb76dde2dac1c13af627167ab9707a60b5fc3058f801d223969e52d3371069
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:c2bbcaeb0d7a30ce4b832e0ba1db814ef9eeedb7c8d66658ce008e388715e922
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:4c2345c9abee4e9db65245c38411721b835d560d49b039cf495a9670325912d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:5c9aafcc6a9808fa261867a25fcb09e47f2075a7ef1f5f301e7eb374cda514f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:c7554bbd0deae642a3f9ecf60fdd59cc264e2d4b7437d8f4eae92e76f2fce954
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:21d9fc02071fbf3b3de117466d0619e769a1bd2d1f90cd5d59e3c18a42dec25a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:200ea1d2e93c351f6fb66df4a8e103d3bffb53802b78837947edbbb4efcbfa79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:3bb4dd6051f4cf0a909a6fcd9784606ee5d326adbec96906018074896a809bf8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:5f6e61b70d6a8ef72f47a66efecc228bc7095f159e1e3f32cd61654885b14e7d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:8b49ec2c7ea20a3c3166094c27473356a01908fd3330963f5a6cae9feb0fe1f6