dhi.io/cloudnative-pg
1.28-debian-fips-dev, 1.28-debian13-fips-dev, 1.28-fips-dev, 1.28.4-debian-fips-dev, 1.28.4-debian13-fips-dev, 1.28.4-fips-dev
sha256:039bbb51f181424157c7aefd5184450005187767d6609dc2fec8c14f285f411a
Manifest digest:sha256:54ab79e9ef78cbf56665af43539847e0bfbd8bd668b930574090470ba69443d6
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:2e6408387a3d46f58827ad9f528b528aebfc85174af2cf60a0f13d3ee8ed9b75 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:b9ecc8bb2f56a8e2a837ec9afaeea44892a0b84499f2469d9493d08e05d3a378 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:1569aa68eaec8d3ade90d498af5ac6cb15d48a822b7a9ef1664b70a1d294f3b7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:58c8ddff75620a633c99015f2825203911e040f528ebd0c3fd34abc0aaf75ac3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:1bfafaaa30e017b0b2cef9f03a112d4ac6bf654839813b225cc8b30284596fcc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:7c3d78145364a41549015656679d38a12a6b67027ca6b6c8a6b73004c612fd53 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:26c7f9e4a5c419ef7eda676f565ca7a5257cffc821ea85977b1b5a6e2ed1a018 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:07c0dee56d2ed95dcb7b401004eae46206c4390236cb9991115c4f047cdcabfb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:17abf90d594d81fab8294976f3aa6f8c51a7c6bb13299cb516d029bfa493e90b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:feab4da450b8e602f35a2669b147174844e99ec852827622c58b0c89faf00758 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:0b6f9aefa1a4459fa442583bfc2471fe0c0e54c2d059fa673d2ee480e3969c33 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:9d54ddddbf1393a255ec47c4926ea658fa7fdc2ab2951852839949cfee0b98d9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:843988c383d7bf0204b4142a9e5af09089eac71ec3c71f5822a27b90d56c676e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:a68388678fd31130b1562b8a76b8323e29b646c6e629f57bea795f168ba8b2ef |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:0f0baeebfe01b4a98f6ae06cbe86596a7d56186c0e3ed275ed066e8b94d22f32 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:adef0d49594b91966f1ce7fc9d8e76b2f0032392001d6c0f320e89787c0b4534 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:1ee0bc226008a839b119987fb069877477db0ade41e943e4ca9ea696786808e1 |