Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev

Index digest:

sha256:34981c0883ba976095ea6b05b9aed825fea0abf9f6bd8b0c43bd4bb9922dca97

Manifest digest:

sha256:fc5a3720ceb0dff007889308ebaa4d527840b4674052659e8aefd5e0b9cf2db2

Size

84.74 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
2
10
1

Support

Ends Jun 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:120f457c85395f6ae878eacc66586094ef7391535ed08a471068a7b22a2439e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:c236acec23a9f8d7a639e77481721f9a84162f202916b8ed8f036825e3128353
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:a99f5dec7bb044791c0e511835ae87664bd3e4b9bcc14b0827ea55ab56aabb66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:2313fc4bd007140b3caa511b56f64de122411e3982926c14fc246b2b33fe5e20
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:498e4f4750e19bbaba144ba36728986d9a2d47b8cd632e9d38819e601ab23a72
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:64f665c352f2dad4984d667d74957b763d21b1e356eee6a54bf0d359b4a61b17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:0cf6ed0c8a935f33a768352e895b248c3ba5cc40c738f4ab086545523e4f70aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:90338be20accae2c8d4cf9825b96bceb8e7c20a4336cf51a2fe76d8edf7646b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:04e3dcf5dc23c9d7f216f9d167595e700802cfb6f2caded4a3bfbf79308250a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:48b63d3bdee561f53a86ad16245d93828f842bd1236a7bb1d4ad7c4dc62b070d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:1b62fbed461c094302ec2d104fff5916f8a3fd1587b07df29428c62a2b4cb79b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:b9a7b51874174b1dc0b49cf46fa007d90ada1fac5154f93a60e0bb97520dbbcd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:a2a0391f293ff19c1d88c7bc04d72f16e1a1aed6268a5bed37d5d32af4d94921
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:9b9195d5ad46a520fcf2866db6f26c054d07590dbebe560bfa554642dc7b5ddb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:85248bdb8dbb5e534c28d746587f35ab932000cabf8516275791e5a39d16c100