dhi.io/cloudnative-pg
1.28, 1.28-debian, 1.28-debian13, 1.28.4, 1.28.4-debian, 1.28.4-debian13
sha256:4e1379235cd4e632ce254481925926253bfb4ff0e9cc430a8b8adcb4b3ba10dc
Manifest digest:sha256:b15be00f2b8be8f3279a7fd72f112000154d50857f81c6d2dd654af56e6e4a4a
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.282. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.28 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:ea60737c7c59a059eda2c548de33b9955a226a0890e6f7e8d1c51d6a249c3513 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:5d5a1cc01601cf08651c65b42f15d800276943100dfbd014fa18ac31cc7aac8c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:12584aff7e98ebe59b2504de632e308d3b2312ab1fb9e54c822a0824086c805d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:b3915d269cd17df56ee59a9c4072076f5620f30cdf08c869cea275f1fb60e82b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:e5806c6a9dce52d9b299159b4c12408447a6b65e6896347fbd6a0bd5a1859664 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:4456609c59f1b78c8d2040cff40a25aa245754de8deb086a9c6e2e037a114f73 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:b2ff218767c17e930346428cfbb193b54a25056823ba4697b5a427754ddea69b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:7341a027be897248e55d9016191a321dccc6b4859d9d1ca9d94ae365d6f1657f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:a978c69cc524e7805faed5d78d077d6bc68bcaa5509abfc9faa96d3e6ee1cbff |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:9333774c7349db7447ca35d9ba71eadba53f4a3dff915ce6bc18d526930a7421 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:3c6bb073a097abe06942210f8d96999484df86206df7b4b64a788371ff74c40e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:8c4ee0b4c09ef9c5e88655dd1d7658cf8b63b0b1cc4bf19cd87263c21d49ec5b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:fc49fa6efef4ffa9353f1fb3a650e3a54ca887a945b39ede02d79cc07a758c83 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:76f380ce129952e9d3fad758fbeeee86e5b8475f55d9ab4ba544eace5ccb3dbb |