dhi.io/cloudnative-pg
1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.3-debian-fips, 1.29.3-debian13-fips, 1.29.3-fips
sha256:f54254c07030591344f9c674722191663a9c4b74e5945637a10d2f313b518c75
Manifest digest:sha256:7c43023aa10852921e14a53d8546ccc4aa6f24f2878185f5f879903c65fa6165
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:d8557e6895b4564cb582a89fee40ca3ac0151dfa6d6812a556b1a610e5486b87 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:6d91656c0b33fe43700023cb3fd363ec2d79247326a160edc8a250d94cd23021 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:f6ef5997ea902ba26e24e058339006e38e84b7729eec5e2c2390371bd82f3146 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:10ebf0fc731421c257ea49c0aa63341292d3be3eedb3983d6b8218932744e8f0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:795418cea7e7c50d11ac9df891f175574abeb8f263a5eb0cfa22a71140f6fc57 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:859314669d8cc47e5fc64bb195adb3bbe032595d386e34cc08a3a693fb1a579d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:26de357b91c8b6f7bd1db32d0ed9a75d3af197c4decfab20f32a9d503f382c81 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:05bdf3e1c5cf50f6ef2fbf80cd1912c27f088d4f8688e345038c1721418a46c1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:79ae5d46f4f3e359e6541521d573c8edfb80611e8b16c496c0ac86c0e4b65c99 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:b072dbe64360f502ab38750de4d58741ad4520618c57685473482b3bcf772d0b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:02ec528141bc1ed1b0c9ac025379df81bb79b48145831128643c4cc0880354e6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:93a99d6ca4020b23c7986a99ba0ac313dc46898500a7e441aed8dda8d57329d8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:016535f4a45299869f82121a7f4de1a373aeca9f76843a39df843bcb0cd4c661 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:ec9364f2e85ba94ed58946be47d8367aa6c2a3a7ab7d91888205235a8ea89866 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:3828d54cc31280b7bfc31041c88be1b8081de500ff193fd87beff5c1f90f9fcb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:749fbec4ab35d09021d1c667434770594c3c264f2e8c9227aa2d3f76c30f70f4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:8766f3a62b3e0033c15fe5f9e1d334acb218324cecd96ce1e691abcd4c083eaa |