Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x

CIS
linux/amd64
debian 13
Tags:

1.28, 1.28-debian, 1.28-debian13, 1.28.4, 1.28.4-debian, 1.28.4-debian13

Index digest:

sha256:c58bb4e1169a438115c55677ff2a45a956e2ab4b7909ffc69b4cefb3c44778c4

Manifest digest:

sha256:426b1a8504fc792673fc4b77b026d1120f1f4e551b9a75d6b4e84f0a04f1783d

Size

30.98 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Ends Jun 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:557d8011279844ea0b2cce6a60eb91d4ef09c7c614ad546e519d903afae56375
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:c7125458e5b4878b2489ea6efbf1391c9a4e8dd7a46db0728888caa35216603d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:415ce6b64503c39f631d8c4abdf196155419aecc9f261187989ea31e623d8797
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:f602a0b5ed4778102ce3d5b6479b92e563c62d667150d3d378673ac7cae1b400
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a1b0552cfb2c68ea33fbd1e1434cb54ab1f122e30e42ec936fb3c216d1792f5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:096bcbe7acbf062bb8078b067397e5a890a8a0d8114f6e90384a308cbe071fbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:da3f2bc723366f8513870c5747cd12aa6ba92c343cc5ffc186735ada1d78654b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:db2e3a8780ffa88d12711df100a21a2d28accb5a095fdb0f38ce5d5e534e510c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:6312c9c83c2be3744a6848fc2fe8f826881c71c5964658ae5c206b40fdfdc871
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:3f38058b1091486bb78b9d4e551a0fb9d69d0f19aca21c3277f84f477e5522b1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:68eb124c304334628a436f38ac5d0d704abbd51057b2235107470f1211e79a41
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:e748ed5de7cf7e90a31ca4bdc46f554c115a5ef6a948c832b66a3f5d73d7b4c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:3e70d7fea4280a305b9207869454a2050de7bcd6678eea23928503cbde242e0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:c84a67eafd2abd86648eff614f18ee362d7489725a06359007886282480a4c88