dhi.io/cloudnative-pg
1.29, 1.29-debian, 1.29-debian13, 1.29.3, 1.29.3-debian, 1.29.3-debian13
sha256:46466245872973bedca3e7f171b499374140b508bfbd05541e606890adf14a82
Manifest digest:sha256:342f824e501eb6d25d861f33b823af58c9bc1bffa8dee76f7fe19e087d1cd356
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.292. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:eb1ebe684ba28d1182888a369bea1b14bd05ad8c2feffadd95bc100897dced51 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:b524c9391334f5e2441af6cbe389593a2ab08f5698fed0aeece9585b060f223d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:3ec505ca31552261d3e6225d409ad8b99b8d3fbf5c81e93486b9fc140690a9b1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:148e32308b81e7ca0a23d68e2bf24d67e1862c7b253c233142210e7531276c41 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:1a94d1f79a5ae3b5c3cd4a79cfb8a54f713eff97e0dfc56ca3dbf65ab18d36d2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:618c4d033844e9956198b8859fb940fa56bb9a42f6ec80d1e5966ec734c5cc28 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:112afbda3ad1171c9068bbccd671c748490721e3818b18970861f68a31de522d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:ab37731307d06acf91948f5187f1e947c0c5d154fd17ef3688232fc48a78da2b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:6713bb507cbcd08d374ac8a3bd3bf12dc53abb7fd4f4e4482be4288d1bd85fe2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:be0aacfb7fe145fece7c9a20bbecec0f2d2225746b659ddfc051c0066d53e5ae |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:8a95b87f59fe929be0d569df94ae3b1fd1000cf5f7832e70ade96c7986a6ea53 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:08d0add45fad7c317723d7fedf52c3c16d4cb90d3536bb7891276a74991271f2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:db7f1b4f2dc1f9a4b6c4aa11c7849d935ee799262657dabcd9d698ca249aa6c4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:5e03bf7c1fe3983f12537122bf08bc8f5fd244d035c4298212cd56879b22fa82 |